PT-2007-5602 · Olate · Olate Download

Imei Addmimistrator

·

Published

2007-08-18

·

Updated

2018-10-15

·

CVE-2007-4421

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Olate Download (od) version 3.4.1
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via an OD3 AutoLogin cookie.
Recommendations For Olate Download (od) version 3.4.1, consider restricting access to the Admin.php file until a patch is available. As a temporary workaround, avoid using the OD3 AutoLogin cookie in the affected application to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4421

Affected Products

Olate Download