PT-2007-5602 · Olate · Olate Download

Imei Addmimistrator

·

Publicado

2007-08-18

·

Atualizado

2018-10-15

·

CVE-2007-4421

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Olate Download (od) version 3.4.1
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via an OD3 AutoLogin cookie.
Recommendations For Olate Download (od) version 3.4.1, consider restricting access to the Admin.php file until a patch is available. As a temporary workaround, avoid using the OD3 AutoLogin cookie in the affected application to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-4421

Produtos afetados

Olate Download