CVE-2007-4084

AlstraSoft Affiliate Network Pro - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to execute arbitrary SQL commands via (1) the pgmid parameter in an uploadProducts action to merchants/index.php and possibly (2) the rowid parameter to merchants/temp.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Lostmon · textwebappsphp
https://www.exploit-db.com/exploits/30371

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37870
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25026
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37869

Scores

EPSS 0.0042
EPSS Percentile 61.8%

Details

Status published
Products (1)
alstrasoft/affiliate_network_pro 8.0
Published Jul 30, 2007
Tracked Since Feb 18, 2026