Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.
References
Configurations
History
21 Nov 2024, 00:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/40423 - | |
References | () http://www.securityfocus.com/bid/24068 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/34398 - | |
References | () https://www.exploit-db.com/exploits/3959 - |
Information
Published : 2007-05-21 23:30
Updated : 2024-11-21 00:31
NVD link : CVE-2007-2777
Mitre link : CVE-2007-2777
CVE.ORG link : CVE-2007-2777
JSON object : View
Products Affected
alstrasoft
- template_seller
CWE