Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.
References
Configurations
History
No history.
Information
Published : 2007-05-21 23:30
Updated : 2017-10-11 01:32
NVD link : CVE-2007-2777
Mitre link : CVE-2007-2777
CVE.ORG link : CVE-2007-2777
JSON object : View
Products Affected
alstrasoft
- template_seller
CWE