PT-2005-2894 · Loki · Loki Download Manager
Salmanooh
·
Published
2005-06-08
·
Updated
2016-10-18
·
CVE-2005-1943
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Loki download manager version 2.0
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the
password field to the "default.asp" endpoint or the cat parameter to the "catinfo.asp" endpoint.Recommendations
For Loki download manager version 2.0, consider restricting access to the "default.asp" and "catinfo.asp" endpoints until a patch is available. As a temporary workaround, avoid using the
password field in the "default.asp" endpoint and the cat parameter in the "catinfo.asp" endpoint to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Loki Download Manager