Back

CVE-2005-3796

Direct static code injection vulnerability in admin_options_manage.php in AlstraSoft Affiliate Network Pro 7.2 allows attackers to execute arbitrary PHP code via the number parameter. NOTE: it is not clear from the original report whether administrator privileges are required. If not, then this does not cross privilege boundaries and is not a vulnerability.

Published: Nov 24, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
alstrasoft affiliate_network_pro 7.2

GitHub Security Advisory GHSA-fwrq-r3hj-6cw4

Direct static code injection vulnerability in admin_options_manage.php in AlstraSoft Affiliate...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.55%

Top 27% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub