alstrasoft records
56 published records for vendor alstrasoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 27
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-255 Credentials Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
56 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2007-2776Proof of concept | AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are mialstrasoft · template seller | Critical10.0 | — | 8.6% | May 21, 2007 |
41Plan | CVE-2007-2775Proof of concept | AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allowsalstrasoft · live support | Critical10.0 | — | 4.5% | May 21, 2007 |
41Plan | CVE-2007-2824Proof of concept | SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commandsalstrasoft · e-friends | Critical10.0 | — | 1.8% | May 22, 2007 |
41Plan | CVE-2008-5649Proof of concept | SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commanalstrasoft · article manager pro · CWE-89 | Critical10.0 | — | 1.8% | Dec 17, 2008 |
33Monitor | CVE-2006-4913Proof of concept | Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary locaalstrasoft · e-friends | High7.5 | — | 9.7% | Sep 20, 2006 |
32Monitor | CVE-2007-2777Proof of concept | Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackersalstrasoft · template seller | High7.5 | — | 6.3% | May 21, 2007 |
31Monitor | CVE-2008-6932Proof of concept | Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploalstrasoft · sendit · CWE-264 | High7.5 | — | 4.8% | Aug 11, 2009 |
31Monitor | CVE-2005-3797Proof of concept | PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbialstrasoft · template seller | High7.5 | — | 3.8% | Nov 24, 2005 |
31Monitor | CVE-2005-0980Proof of concept | PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by modalstrasoft · epay | High7.5 | — | 2.7% | May 2, 2005 |
31Monitor | CVE-2006-4443Proof of concept | PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary Palstrasoft · video share enterprise | High7.5 | — | 2.6% | Aug 29, 2006 |
31Monitor | CVE-2006-4591Proof of concept | Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remalstrasoft · template seller | High7.5 | — | 2.5% | Sep 6, 2006 |
31Monitor | CVE-2008-3240Proof of concept | SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via talstrasoft · affiliate network pro · CWE-89 | High7.5 | — | 2.4% | Jul 21, 2008 |
31Monitor | CVE-2007-2017No exploit | siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modifyalstrasoft · video share enterprise | High7.5 | — | 1.8% | Apr 12, 2007 |
31Monitor | CVE-2005-3062No exploit | PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via talstrasoft · e-friends | High7.5 | — | 1.7% | Sep 27, 2005 |
30Monitor | CVE-2006-6818No exploit | AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/calstrasoft · webhost directory | High7.5 | — | 1.7% | Dec 29, 2006 |
30Monitor | CVE-2005-3796No exploit | Direct static code injection vulnerability in admin_options_manage.php in AlstraSoft Affiliate Network Pro 7.2 allows attackers to execute aalstrasoft · affiliate network pro | High7.5 | — | 1.5% | Nov 24, 2005 |
30Monitor | CVE-2005-3793No exploit | Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to bypass authentication and execute aalstrasoft · affiliate network pro | High7.5 | — | 1.5% | Nov 24, 2005 |
30Monitor | CVE-2005-3798No exploit | SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL commaalstrasoft · template seller | High7.5 | — | 1.4% | Nov 24, 2005 |
30Monitor | CVE-2006-2616No exploit | SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows ralstrasoft · webhost directory | High7.5 | — | 1.4% | May 25, 2006 |
30Monitor | CVE-2007-6106Proof of concept | SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands alstrasoft · e-friends · CWE-89 | High7.5 | — | 1.4% | Nov 23, 2007 |
30Monitor | CVE-2006-2565No exploit | SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the authalstrasoft · article manager pro | High7.5 | — | 1.3% | May 24, 2006 |
30Monitor | CVE-2008-3954Proof of concept | SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commandsalstrasoft · forum pay per post exchange · CWE-89 | High7.5 | — | 1.2% | Sep 10, 2008 |
30Monitor | CVE-2008-0429Proof of concept | SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commalstrasoft · forum pay per post exchange · CWE-89 | High7.5 | — | 1.2% | Jan 23, 2008 |
30Monitor | CVE-2008-5650Proof of concept | SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL commandalstrasoft · webhost directory · CWE-89 | High7.5 | — | 1.1% | Dec 17, 2008 |
30Monitor | CVE-2008-3386Proof of concept | SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commandsalstrasoft · video share enterprise · CWE-89 | High7.5 | — | 1.0% | Jul 30, 2008 |
- CVE-2007-277643Plan
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are mi
CriticalCVSS 10.0Proof of conceptEPSS 9%alstrasoft · template sellerMay 21, 2007
- CVE-2007-277541Plan
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows
CriticalCVSS 10.0Proof of conceptEPSS 5%alstrasoft · live supportMay 21, 2007
- CVE-2007-282441Plan
SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands
CriticalCVSS 10.0Proof of conceptEPSS 2%alstrasoft · e-friendsMay 22, 2007
- CVE-2008-564941Plan
SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL comman
CriticalCVSS 10.0Proof of conceptEPSS 2%alstrasoft · article manager proDec 17, 2008
- CVE-2006-491333Monitor
Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary loca
HighCVSS 7.5Proof of conceptEPSS 10%alstrasoft · e-friendsSep 20, 2006
- CVE-2007-277732Monitor
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers
HighCVSS 7.5Proof of conceptEPSS 6%alstrasoft · template sellerMay 21, 2007
- CVE-2008-693231Monitor
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uplo
HighCVSS 7.5Proof of conceptEPSS 5%alstrasoft · senditAug 11, 2009
- CVE-2005-379731Monitor
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbi
HighCVSS 7.5Proof of conceptEPSS 4%alstrasoft · template sellerNov 24, 2005
- CVE-2005-098031Monitor
PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by mod
HighCVSS 7.5Proof of conceptEPSS 3%alstrasoft · epayMay 2, 2005
- CVE-2006-444331Monitor
PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary P
HighCVSS 7.5Proof of conceptEPSS 3%alstrasoft · video share enterpriseAug 29, 2006
- CVE-2006-459131Monitor
Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow rem
HighCVSS 7.5Proof of conceptEPSS 3%alstrasoft · template sellerSep 6, 2006
- CVE-2008-324031Monitor
SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via t
HighCVSS 7.5Proof of conceptEPSS 2%alstrasoft · affiliate network proJul 21, 2008
- CVE-2007-201731Monitor
siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify
HighCVSS 7.5No exploitEPSS 2%alstrasoft · video share enterpriseApr 12, 2007
- CVE-2005-306231Monitor
PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via t
HighCVSS 7.5No exploitEPSS 2%alstrasoft · e-friendsSep 27, 2005
- CVE-2006-681830Monitor
AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/c
HighCVSS 7.5No exploitEPSS 2%alstrasoft · webhost directoryDec 29, 2006
- CVE-2005-379630Monitor
Direct static code injection vulnerability in admin_options_manage.php in AlstraSoft Affiliate Network Pro 7.2 allows attackers to execute a
HighCVSS 7.5No exploitEPSS 2%alstrasoft · affiliate network proNov 24, 2005
- CVE-2005-379330Monitor
Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to bypass authentication and execute a
HighCVSS 7.5No exploitEPSS 1%alstrasoft · affiliate network proNov 24, 2005
- CVE-2005-379830Monitor
SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL comma
HighCVSS 7.5No exploitEPSS 1%alstrasoft · template sellerNov 24, 2005
- CVE-2006-261630Monitor
SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows r
HighCVSS 7.5No exploitEPSS 1%alstrasoft · webhost directoryMay 25, 2006
- CVE-2007-610630Monitor
SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%alstrasoft · e-friendsNov 23, 2007
- CVE-2006-256530Monitor
SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the auth
HighCVSS 7.5No exploitEPSS 1%alstrasoft · article manager proMay 24, 2006
- CVE-2008-395430Monitor
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%alstrasoft · forum pay per post exchangeSep 10, 2008
- CVE-2008-042930Monitor
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL comm
HighCVSS 7.5Proof of conceptEPSS 1%alstrasoft · forum pay per post exchangeJan 23, 2008
- CVE-2008-565030Monitor
SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL command
HighCVSS 7.5Proof of conceptEPSS 1%alstrasoft · webhost directoryDec 17, 2008
- CVE-2008-338630Monitor
SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%alstrasoft · video share enterpriseJul 30, 2008