AlstraSoft Affiliate Network Pro "fl" Parameter File Download Vulnerability
Description
A vulnerability has been identified in AlstraSoft Affiliate Network Pro, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "admin/downloadbackup.php" script that does not validate the "fl" parameter before being passed as an argument to a "readfile()" call, which could be exploited by attackers to download arbitrary files from a vulnerable server via directory traversal attacks.
Vulnerable Products
Vulnerable Software: AlstraSoft Affiliate Network Pro version 7.4 and prior