CVE-2007-2777
Last modified
CVE-2007-2777 is a vulnerability of currently unknown severity. Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.. EPSS estimates a 6.32% chance of exploitation in the next 30 days.
Description
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alstrasoft | Template Seller | <= 3.25 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2777?
How severe is CVE-2007-2777?
How do I fix CVE-2007-2777?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2771Stack-based buffer overflow in the LEAD Technologies LeadToo…
- CVE-2007-2772(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc…
- CVE-2007-2773SQL injection vulnerability in plugins/mp3playlist/mp3playli…
- CVE-2007-2774Multiple PHP remote file inclusion vulnerabilities in SunLig…
- CVE-2007-2775AlstraSoft Live Support 1.21 sends a redirect to the web bro…
- CVE-2007-2776AlstraSoft Template Seller Pro 3.25 and earlier sends a redi…
- CVE-2007-2778Multiple directory traversal vulnerabilities in MolyX BOARD …
- CVE-2007-2779PHP remote file inclusion vulnerability in template_csv.php …
- CVE-2007-2780PsychoStats 3.0.6b and earlier allows remote attackers to ob…
- CVE-2007-2781Cross-site scripting (XSS) vulnerability in include/sessionR…
- CVE-2007-2782Packeteer PacketShaper uses fixed increments in TCP initial …
- CVE-2007-2783Unspecified vulnerability in Rational Soft Hidden Administra…
Are you affected by CVE-2007-2777?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
