Alstrasoft's vulnerability footprint spans a modest but well-represented collection of web-based and hosting-related products, including affiliate network, video sharing, web directory, and social collaboration platforms. The vendor's disclosures concentrate on application-layer input-handling weaknesses, dominated by SQL injection and cross-site scripting vulnerabilities that are characteristic of server-side web applications, alongside a broad category of other structural flaws. Notably, vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the relative accessibility of web application attack surfaces and the appeal of such vulnerabilities to security researchers and tool developers. Defenders should prioritize input-validation hardening and parameterized queries across this vendor's products; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alstrasoft over time
Signals from CVEs in this vendor scope (56 CVEs).
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2776HIGH AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to | May 21, 2007 | 10.0 | 38 | NO | YES |
CVE-2007-2824HIGH SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal acti | May 22, 2007 | 10.0 | 36 | NO | YES |
CVE-2007-2775HIGH AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrati | May 21, 2007 | 10.0 | 36 | NO | YES |
CVE-2008-5649HIGH SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via the username parameter. | Dec 17, 2008 | 10.0 | 35 | NO | YES |
CVE-2006-4913HIGH Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary c | Sep 21, 2006 | 7.5 | 32 | NO | YES |
CVE-2007-2017HIGH siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request. | Apr 12, 2007 | 7.5 | 31 | NO | NO |
CVE-2008-6932HIGH Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a file with an executable extensio | Aug 11, 2009 | 7.5 | 30 | NO | YES |
CVE-2007-4085MEDIUM Multiple SQL injection vulnerabilities in AlstraSoft AskMe Pro allow remote attackers to execute arbitrary SQL commands via the (1) que_id parameter to forum_answer.php or (2) the | Jul 30, 2007 | 6.8 | 30 | NO | YES |
CVE-2007-2777HIGH Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an ar | May 21, 2007 | 7.5 | 30 | NO | YES |
CVE-2005-3797HIGH PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] | Nov 24, 2005 | 7.5 | 29 | NO | YES |
Signals from CVEs in this vendor scope (56 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alstrasoft.
Media articles that mention a CVE ID that affects a product developed by Alstrasoft — matched by CVE ID, not by vendor name.