Multiple unspecified vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to include local files and have other unspecified impact, related to incorrect input validation or other defects involving (1) admin/backupstart.php, (2) a .sql filename under admin/admin/dump/, (3) a .sql filename in the fl parameter to admin/downloadbackup.php, and (4) a .. (dot dot) in the fl parameter to admin/downloadbackup.php.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2007-10-05T00:00:00
Updated: 2024-08-07T15:24:42.336Z
Reserved: 2007-10-04T00:00:00
Link: CVE-2007-5223
Vulnrichment
No data.
NVD
Status : Modified
Published: 2007-10-05T00:17:00.000
Modified: 2024-11-21T00:37:24.847
Link: CVE-2007-5223
Redhat
No data.