Show filters
56 Total Results
Displaying 21-30 of 56
Sort by:
Attacker Value
Unknown

CVE-2007-4082

Disclosure Date: July 30, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in contact_author.php AlstraSoft Article Manager Pro allows remote attackers to inject arbitrary web script or HTML via the userid parameter.
0
Attacker Value
Unknown

CVE-2007-4077

Disclosure Date: July 30, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Video Share Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) msg, (2) page, (3) viewkey, or (4) viewtype parameter to (a) view_video.php; the (5) next parameter to (b) signup.php; the (6) search_id parameter to (c) search_result.php; the (7) category or (8) page parameter to (d) video.php; the (9) receiver parameter to (e) compose.php; the (10) catgy parameter to (f) groups.php; the (11) channelname parameter to (g) siteadmin/channels.php; or the (12) uname parameter to (h) siteadmin/muser.php.
0
Attacker Value
Unknown

CVE-2007-4079

Disclosure Date: July 30, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft SMS Text Messaging Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) q parameter to (a) admin/membersearch.php, or (3) the userid parameter to (b) admin/edituser.php.
0
Attacker Value
Unknown

CVE-2007-4085

Disclosure Date: July 30, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in AlstraSoft AskMe Pro allow remote attackers to execute arbitrary SQL commands via the (1) que_id parameter to forum_answer.php or (2) the cat_id parameter to search.php.
0
Attacker Value
Unknown

CVE-2007-2824

Disclosure Date: May 22, 2007 (last updated October 04, 2023)
SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal action for index.php.
0
Attacker Value
Unknown

CVE-2007-2777

Disclosure Date: May 21, 2007 (last updated October 04, 2023)
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.
0
Attacker Value
Unknown

CVE-2007-2775

Disclosure Date: May 21, 2007 (last updated October 04, 2023)
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php.
0
Attacker Value
Unknown

CVE-2007-2776

Disclosure Date: May 21, 2007 (last updated October 04, 2023)
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php.
0
Attacker Value
Unknown

CVE-2007-2017

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request.
0
Attacker Value
Unknown

CVE-2007-2018

Disclosure Date: April 12, 2007 (last updated October 04, 2023)
SQL injection vulnerability in msg.php in AlstraSoft Video Share Enterprise allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
0