Vulnerabilities > CVE-2005-3795 - Cross-Site Scripting vulnerability in Alstrasoft Affiliate Network PRO 7.2

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
alstrasoft

Summary

Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to inject arbitrary web script or HTML via (1) the Err parameter in admin/index.php and the (2) firstname and (3) lastname parameters in index.php.

Vulnerable Configurations

Part Description Count
Application
Alstrasoft
1