7.5
CVSSv2

CVE-2007-4084

Published: 30/07/2007 Updated: 15/11/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro allow remote malicious users to execute arbitrary SQL commands via (1) the pgmid parameter in an uploadProducts action to merchants/index.php and possibly (2) the rowid parameter to merchants/temp.php.

Vulnerable Product Search on Vulmon Subscribe to Product

alstrasoft affiliate network pro 8.0

Exploits

source: wwwsecurityfocuscom/bid/25026/info AlstraSoft Affiliate Network Pro is affected by multiple input-validation vulnerabilities These issues include multiple cross-site scripting isues and SQL-injection issues A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerab ...