CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2006-4591

HIGH
7.5
CVSS Severity Score
EPSS Score0.0920%
EPSS Percentile25.25th
Published2006年9月6日
Last Modified2026年4月16日

Vulnerability Description

Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attackers to execute arbitrary PHP code via a URL in the config[template_path] parameter to (1) payment/payment_result.php or (2) /payment/spuser_result.php.

Affected Platforms (CPE)

📦
Alstrasoft

Template Seller

All versions
📦
Alstrasoft

Template Seller

All versions
📦
Alstrasoft

Template Seller

= 3.25

References & Advisories

相關漏洞威脅