Skip to content
Noroxi

alstrasoft records

56 published records for vendor alstrasoft.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
27
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

56 records
  • AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are mi

    CriticalCVSS 10.0Proof of conceptEPSS 9%

    alstrasoft · template sellerMay 21, 2007

  • AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows

    CriticalCVSS 10.0Proof of conceptEPSS 5%

    alstrasoft · live supportMay 21, 2007

  • SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands

    CriticalCVSS 10.0Proof of conceptEPSS 2%

    alstrasoft · e-friendsMay 22, 2007

  • SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL comman

    CriticalCVSS 10.0Proof of conceptEPSS 2%

    alstrasoft · article manager proDec 17, 2008

  • CVE-2006-4913
    33Monitor

    Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary loca

    HighCVSS 7.5Proof of conceptEPSS 10%

    alstrasoft · e-friendsSep 20, 2006

  • CVE-2007-2777
    32Monitor

    Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers

    HighCVSS 7.5Proof of conceptEPSS 6%

    alstrasoft · template sellerMay 21, 2007

  • CVE-2008-6932
    31Monitor

    Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uplo

    HighCVSS 7.5Proof of conceptEPSS 5%

    alstrasoft · senditAug 11, 2009

  • CVE-2005-3797
    31Monitor

    PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbi

    HighCVSS 7.5Proof of conceptEPSS 4%

    alstrasoft · template sellerNov 24, 2005

  • CVE-2005-0980
    31Monitor

    PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by mod

    HighCVSS 7.5Proof of conceptEPSS 3%

    alstrasoft · epayMay 2, 2005

  • CVE-2006-4443
    31Monitor

    PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary P

    HighCVSS 7.5Proof of conceptEPSS 3%

    alstrasoft · video share enterpriseAug 29, 2006

  • CVE-2006-4591
    31Monitor

    Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow rem

    HighCVSS 7.5Proof of conceptEPSS 3%

    alstrasoft · template sellerSep 6, 2006

  • CVE-2008-3240
    31Monitor

    SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via t

    HighCVSS 7.5Proof of conceptEPSS 2%

    alstrasoft · affiliate network proJul 21, 2008

  • CVE-2007-2017
    31Monitor

    siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify

    HighCVSS 7.5No exploitEPSS 2%

    alstrasoft · video share enterpriseApr 12, 2007

  • CVE-2005-3062
    31Monitor

    PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via t

    HighCVSS 7.5No exploitEPSS 2%

    alstrasoft · e-friendsSep 27, 2005

  • CVE-2006-6818
    30Monitor

    AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/c

    HighCVSS 7.5No exploitEPSS 2%

    alstrasoft · webhost directoryDec 29, 2006

  • CVE-2005-3796
    30Monitor

    Direct static code injection vulnerability in admin_options_manage.php in AlstraSoft Affiliate Network Pro 7.2 allows attackers to execute a

    HighCVSS 7.5No exploitEPSS 2%

    alstrasoft · affiliate network proNov 24, 2005

  • CVE-2005-3793
    30Monitor

    Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to bypass authentication and execute a

    HighCVSS 7.5No exploitEPSS 1%

    alstrasoft · affiliate network proNov 24, 2005

  • CVE-2005-3798
    30Monitor

    SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL comma

    HighCVSS 7.5No exploitEPSS 1%

    alstrasoft · template sellerNov 24, 2005

  • CVE-2006-2616
    30Monitor

    SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows r

    HighCVSS 7.5No exploitEPSS 1%

    alstrasoft · webhost directoryMay 25, 2006

  • CVE-2007-6106
    30Monitor

    SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands

    HighCVSS 7.5Proof of conceptEPSS 1%

    alstrasoft · e-friendsNov 23, 2007

  • CVE-2006-2565
    30Monitor

    SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the auth

    HighCVSS 7.5No exploitEPSS 1%

    alstrasoft · article manager proMay 24, 2006

  • CVE-2008-3954
    30Monitor

    SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands

    HighCVSS 7.5Proof of conceptEPSS 1%

    alstrasoft · forum pay per post exchangeSep 10, 2008

  • CVE-2008-0429
    30Monitor

    SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL comm

    HighCVSS 7.5Proof of conceptEPSS 1%

    alstrasoft · forum pay per post exchangeJan 23, 2008

  • CVE-2008-5650
    30Monitor

    SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL command

    HighCVSS 7.5Proof of conceptEPSS 1%

    alstrasoft · webhost directoryDec 17, 2008

  • CVE-2008-3386
    30Monitor

    SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commands

    HighCVSS 7.5Proof of conceptEPSS 1%

    alstrasoft · video share enterpriseJul 30, 2008