Vulnerability index

Browse CVEs

43 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sendit HIGH 7.5
CVE-2008-6932

Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a f…

No fix yet
Fix from $1,950 2009-08-11
Web Email Script Enterprise HIGH 7.5
CVE-2008-5751

SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to execute arbitrary SQL commands vi…

No fix yet
Fix from $1,950 2008-12-30
Article Manager Pro HIGH 10.0
CVE-2008-5649

SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via th…

No fix yet
Fix from $1,950 2008-12-17
Webhost Directory HIGH 7.5
CVE-2008-5650

SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL commands via the…

No fix yet
Fix from $1,950 2008-12-17
Forum Pay Per Post Exchange HIGH 7.5
CVE-2008-3954

SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands via the …

No fix yet
Fix from $1,950 2008-09-11
Video Share Enterprise HIGH 7.5
CVE-2008-3386

SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commands via the …

No fix yet
Fix from $1,950 2008-07-30
Affiliate Network Pro HIGH 7.5
CVE-2008-3240

SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via the pgm pa…

No fix yet
Fix from $1,950 2008-07-21
Askme Pro HIGH 7.5
CVE-2008-2902

SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the …

Fix: after 2.1
Fix from $1,950 2008-06-30
Askme MEDIUM 5.0
CVE-2008-2857

AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive …

Fix: after 2.1
Fix from $1,600 2008-06-25
Forum Pay Per Post Exchange MEDIUM 5.0
CVE-2008-0440

AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts.

No fix yet
Fix from $1,600 2008-01-23
Forum Pay Per Post Exchange HIGH 7.5
CVE-2008-0429

SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via …

No fix yet
Fix from $1,950 2008-01-23
E Friends HIGH 7.5
CVE-2007-6106

SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands via the s…

Fix: after 4.98
Fix from $1,950 2007-11-23
Affiliate Network Pro MEDIUM 6.8
CVE-2007-5223

Multiple unspecified vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to include local files and have other unspecified imp…

Mitigation only
Fix from $1,600 2007-10-05
Affiliate Network Pro HIGH 7.5
CVE-2007-4084

Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to execute arbitrary SQL commands via (1) the pgmid…

No fix yet
Fix from $1,950 2007-07-30
Askme Pro MEDIUM 6.8
CVE-2007-4085

Multiple SQL injection vulnerabilities in AlstraSoft AskMe Pro allow remote attackers to execute arbitrary SQL commands via the (1) que_id parameter …

No fix yet
Fix from $1,600 2007-07-30
Video Share Enterprise MEDIUM 6.8
CVE-2007-4086

Multiple SQL injection vulnerabilities in AlstraSoft Video Share Enterprise allow remote attackers to execute arbitrary SQL commands via (1) the gid …

No fix yet
Fix from $1,600 2007-07-30
E Friends MEDIUM 6.4
CVE-2007-4080

Cross-site scripting (XSS) vulnerability in index.php AlstraSoft E-Friends allows remote attackers to inject arbitrary web script or HTML via the p_i…

No fix yet
Fix from $1,600 2007-07-30
E Friends HIGH 10.0
CVE-2007-2824

SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the …

Fix: after 4.21
Fix from $1,950 2007-05-22
Live Support HIGH 10.0
CVE-2007-2775

AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote a…

No fix yet
Fix from $1,950 2007-05-21
Template Seller HIGH 10.0
CVE-2007-2776EPSS 9%

AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, wh…

Fix: after 3.25
Fix from $1,950 2007-05-21
Template Seller HIGH 7.5
CVE-2007-2777EPSS 6%

Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execu…

Fix: after 3.25
Fix from $1,950 2007-05-21
Video Share Enterprise HIGH 7.5
CVE-2007-2017

siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user inf…

Fix: after 4.3
Fix from $1,950 2007-04-12
Video Share Enterprise MEDIUM 6.5
CVE-2007-2018

SQL injection vulnerability in msg.php in AlstraSoft Video Share Enterprise allows remote authenticated users to execute arbitrary SQL commands via t…

Fix: after 4.3
Fix from $1,600 2007-04-12
Webhost Directory HIGH 7.5
CVE-2006-6818

AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.

Mitigation only
Fix from $1,950 2006-12-29
Webhost Directory MEDIUM 6.4
CVE-2006-6819

AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to down…

Mitigation only
Fix from $1,600 2006-12-29
Webhost Directory MEDIUM 5.0
CVE-2006-6817

AlstraSoft Web Host Directory allows remote attackers to obtain sensitive information by requesting any invalid URI, which reveals the path in an err…

Mitigation only
Fix from $1,600 2006-12-29
E Friends HIGH 7.5
CVE-2006-4913EPSS 10%

Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files a…

No fix yet
Fix from $1,950 2006-09-21
Template Seller HIGH 7.5
CVE-2006-4591

Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attac…

No fix yet
Fix from $1,950 2006-09-06
Video Share Enterprise HIGH 7.5
CVE-2006-4443

PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to execute arbitrary PHP code v…

No fix yet
Fix from $1,950 2006-08-29
Webhost Directory HIGH 7.5
CVE-2006-2616

SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote att…

Mitigation only
Fix from $1,950 2006-05-26