alstrasoft kayıtları
alstrasoft üreticisine ait 56 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 27
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-255 Credentials Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
56 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2007-2776Kavram kanıtı | AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are mialstrasoft · template seller | Kritik10,0 | — | %8,6 | 21 May 2007 |
41Planlayın | CVE-2007-2775Kavram kanıtı | AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allowsalstrasoft · live support | Kritik10,0 | — | %4,5 | 21 May 2007 |
41Planlayın | CVE-2007-2824Kavram kanıtı | SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commandsalstrasoft · e-friends | Kritik10,0 | — | %1,8 | 22 May 2007 |
41Planlayın | CVE-2008-5649Kavram kanıtı | SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commanalstrasoft · article manager pro · CWE-89 | Kritik10,0 | — | %1,8 | 17 Ara 2008 |
33İzleyin | CVE-2006-4913Kavram kanıtı | Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary locaalstrasoft · e-friends | Yüksek7,5 | — | %9,7 | 20 Eyl 2006 |
32İzleyin | CVE-2007-2777Kavram kanıtı | Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackersalstrasoft · template seller | Yüksek7,5 | — | %6,3 | 21 May 2007 |
31İzleyin | CVE-2008-6932Kavram kanıtı | Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploalstrasoft · sendit · CWE-264 | Yüksek7,5 | — | %4,8 | 11 Ağu 2009 |
31İzleyin | CVE-2005-3797Kavram kanıtı | PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbialstrasoft · template seller | Yüksek7,5 | — | %3,8 | 24 Kas 2005 |
31İzleyin | CVE-2005-0980Kavram kanıtı | PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by modalstrasoft · epay | Yüksek7,5 | — | %2,7 | 2 May 2005 |
31İzleyin | CVE-2006-4443Kavram kanıtı | PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary Palstrasoft · video share enterprise | Yüksek7,5 | — | %2,6 | 29 Ağu 2006 |
31İzleyin | CVE-2006-4591Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remalstrasoft · template seller | Yüksek7,5 | — | %2,5 | 6 Eyl 2006 |
31İzleyin | CVE-2008-3240Kavram kanıtı | SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via talstrasoft · affiliate network pro · CWE-89 | Yüksek7,5 | — | %2,4 | 21 Tem 2008 |
31İzleyin | CVE-2007-2017İstismar yok | siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modifyalstrasoft · video share enterprise | Yüksek7,5 | — | %1,8 | 12 Nis 2007 |
31İzleyin | CVE-2005-3062İstismar yok | PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via talstrasoft · e-friends | Yüksek7,5 | — | %1,7 | 27 Eyl 2005 |
30İzleyin | CVE-2006-6818İstismar yok | AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/calstrasoft · webhost directory | Yüksek7,5 | — | %1,7 | 29 Ara 2006 |
30İzleyin | CVE-2005-3796İstismar yok | Direct static code injection vulnerability in admin_options_manage.php in AlstraSoft Affiliate Network Pro 7.2 allows attackers to execute aalstrasoft · affiliate network pro | Yüksek7,5 | — | %1,5 | 24 Kas 2005 |
30İzleyin | CVE-2005-3793İstismar yok | Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to bypass authentication and execute aalstrasoft · affiliate network pro | Yüksek7,5 | — | %1,5 | 24 Kas 2005 |
30İzleyin | CVE-2005-3798İstismar yok | SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL commaalstrasoft · template seller | Yüksek7,5 | — | %1,4 | 24 Kas 2005 |
30İzleyin | CVE-2006-2616İstismar yok | SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows ralstrasoft · webhost directory | Yüksek7,5 | — | %1,4 | 25 May 2006 |
30İzleyin | CVE-2007-6106Kavram kanıtı | SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands alstrasoft · e-friends · CWE-89 | Yüksek7,5 | — | %1,4 | 23 Kas 2007 |
30İzleyin | CVE-2006-2565İstismar yok | SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the authalstrasoft · article manager pro | Yüksek7,5 | — | %1,3 | 24 May 2006 |
30İzleyin | CVE-2008-3954Kavram kanıtı | SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commandsalstrasoft · forum pay per post exchange · CWE-89 | Yüksek7,5 | — | %1,2 | 10 Eyl 2008 |
30İzleyin | CVE-2008-0429Kavram kanıtı | SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commalstrasoft · forum pay per post exchange · CWE-89 | Yüksek7,5 | — | %1,2 | 23 Oca 2008 |
30İzleyin | CVE-2008-5650Kavram kanıtı | SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL commandalstrasoft · webhost directory · CWE-89 | Yüksek7,5 | — | %1,1 | 17 Ara 2008 |
30İzleyin | CVE-2008-3386Kavram kanıtı | SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commandsalstrasoft · video share enterprise · CWE-89 | Yüksek7,5 | — | %1,0 | 30 Tem 2008 |
- CVE-2007-277643Planlayın
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are mi
KritikCVSS 10,0Kavram kanıtıEPSS %9alstrasoft · template seller21 May 2007
- CVE-2007-277541Planlayın
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows
KritikCVSS 10,0Kavram kanıtıEPSS %5alstrasoft · live support21 May 2007
- CVE-2007-282441Planlayın
SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands
KritikCVSS 10,0Kavram kanıtıEPSS %2alstrasoft · e-friends22 May 2007
- CVE-2008-564941Planlayın
SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL comman
KritikCVSS 10,0Kavram kanıtıEPSS %2alstrasoft · article manager pro17 Ara 2008
- CVE-2006-491333İzleyin
Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary loca
YüksekCVSS 7,5Kavram kanıtıEPSS %10alstrasoft · e-friends20 Eyl 2006
- CVE-2007-277732İzleyin
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers
YüksekCVSS 7,5Kavram kanıtıEPSS %6alstrasoft · template seller21 May 2007
- CVE-2008-693231İzleyin
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uplo
YüksekCVSS 7,5Kavram kanıtıEPSS %5alstrasoft · sendit11 Ağu 2009
- CVE-2005-379731İzleyin
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbi
YüksekCVSS 7,5Kavram kanıtıEPSS %4alstrasoft · template seller24 Kas 2005
- CVE-2005-098031İzleyin
PHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by mod
YüksekCVSS 7,5Kavram kanıtıEPSS %3alstrasoft · epay2 May 2005
- CVE-2006-444331İzleyin
PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary P
YüksekCVSS 7,5Kavram kanıtıEPSS %3alstrasoft · video share enterprise29 Ağu 2006
- CVE-2006-459131İzleyin
Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow rem
YüksekCVSS 7,5Kavram kanıtıEPSS %3alstrasoft · template seller6 Eyl 2006
- CVE-2008-324031İzleyin
SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via t
YüksekCVSS 7,5Kavram kanıtıEPSS %2alstrasoft · affiliate network pro21 Tem 2008
- CVE-2007-201731İzleyin
siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify
YüksekCVSS 7,5İstismar yokEPSS %2alstrasoft · video share enterprise12 Nis 2007
- CVE-2005-306231İzleyin
PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via t
YüksekCVSS 7,5İstismar yokEPSS %2alstrasoft · e-friends27 Eyl 2005
- CVE-2006-681830İzleyin
AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/c
YüksekCVSS 7,5İstismar yokEPSS %2alstrasoft · webhost directory29 Ara 2006
- CVE-2005-379630İzleyin
Direct static code injection vulnerability in admin_options_manage.php in AlstraSoft Affiliate Network Pro 7.2 allows attackers to execute a
YüksekCVSS 7,5İstismar yokEPSS %2alstrasoft · affiliate network pro24 Kas 2005
- CVE-2005-379330İzleyin
Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to bypass authentication and execute a
YüksekCVSS 7,5İstismar yokEPSS %1alstrasoft · affiliate network pro24 Kas 2005
- CVE-2005-379830İzleyin
SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL comma
YüksekCVSS 7,5İstismar yokEPSS %1alstrasoft · template seller24 Kas 2005
- CVE-2006-261630İzleyin
SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows r
YüksekCVSS 7,5İstismar yokEPSS %1alstrasoft · webhost directory25 May 2006
- CVE-2007-610630İzleyin
SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %1alstrasoft · e-friends23 Kas 2007
- CVE-2006-256530İzleyin
SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the auth
YüksekCVSS 7,5İstismar yokEPSS %1alstrasoft · article manager pro24 May 2006
- CVE-2008-395430İzleyin
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %1alstrasoft · forum pay per post exchange10 Eyl 2008
- CVE-2008-042930İzleyin
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL comm
YüksekCVSS 7,5Kavram kanıtıEPSS %1alstrasoft · forum pay per post exchange23 Oca 2008
- CVE-2008-565030İzleyin
SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL command
YüksekCVSS 7,5Kavram kanıtıEPSS %1alstrasoft · webhost directory17 Ara 2008
- CVE-2008-338630İzleyin
SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %1alstrasoft · video share enterprise30 Tem 2008