CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14998  CVE-2005-3794  Candidate  AlstraSoft Affiliate Network Pro 7.2 allows remote attackers to obtain sensitive information via a direct request to scripts such as (1) togateway.php and (2) other unspecified scripts.  Assigned (20051124)  None (candidate not yet proposed)    View
14999  CVE-2005-3795  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to inject arbitrary web script or HTML via (1) the Err parameter in admin/index.php and the (2) firstname and (3) lastname parameters in index.php.  Assigned (20051124)  None (candidate not yet proposed)    View
15000  CVE-2005-3796  Candidate  Direct static code injection vulnerability in admin_options_manage.php in AlstraSoft Affiliate Network Pro 7.2 allows attackers to execute arbitrary PHP code via the number parameter. NOTE: it is not clear from the original report whether administrator privileges are required. If not, then this does not cross privilege boundaries and is not a vulnerability.  Assigned (20051124)  None (candidate not yet proposed)    View
15001  CVE-2005-3797  Candidate  PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] parameter.  Assigned (20051124)  None (candidate not yet proposed)    View
15002  CVE-2005-3798  Candidate  SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL commands via the username field.  Assigned (20051124)  None (candidate not yet proposed)    View

Page 18680 of 20943, showing 5 records out of 104715 total, starting on record 93396, ending on 93400

Actions