CyberSec.Space Logo
Back to CVE Browser

CVE-2006-4591

HIGH
7.5
CVSS Severity Score
EPSS Score0.0920%
EPSS Percentile25.25th
PublishedSep 6, 2006
Last ModifiedApr 16, 2026

Vulnerability Description

Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attackers to execute arbitrary PHP code via a URL in the config[template_path] parameter to (1) payment/payment_result.php or (2) /payment/spuser_result.php.

Affected Platforms (CPE)

πŸ“¦
Alstrasoft

Template Seller

All versions
πŸ“¦
Alstrasoft

Template Seller

All versions
πŸ“¦
Alstrasoft

Template Seller

= 3.25

References & Advisories

Related Vulnerabilities