Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to bypass authentication and execute arbitrary SQL commands via the (1) username or (2) password to admin/admin_validate_login, or the (3) login, (4) password, and (5) flag parameters to login_validate.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Affiliate_network_pro | Alstrasoft | 7.2 (including) | 7.2 (including) |