CVE-2005-3793

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/11/2005
Last modified:
03/04/2025

Description

Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to bypass authentication and execute arbitrary SQL commands via the (1) username or (2) password to admin/admin_validate_login, or the (3) login, (4) password, and (5) flag parameters to login_validate.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:alstrasoft:affiliate_network_pro:7.2:*:*:*:*:*:*:*