Skip to main content

Vendor/product archive

olate / olatedownload CVEs

Beta · best-effort

7 CVEs tagged to olate / olatedownload2 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2007-4540

Published Aug 27, 2007

Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute arbitrary SQL commands via the (1) HTTP_REFERER or (2) HTTP_U…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4541

Published Aug 27, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the PHP_SELF variable in mod…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4454

Published Aug 21, 2007

Eval injection vulnerability in environment.php in Olate Download (od) 3.4.1 allows context-dependent attackers to execute arbitrary code via a crafted version string, as referenc…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4419

Published Aug 18, 2007

Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4421

Published Aug 18, 2007

SQL injection vulnerability in Admin.php in Olate Download (od) 3.4.1 allows remote attackers to execute arbitrary SQL commands via an OD3_AutoLogin cookie.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5144

Published Oct 5, 2006

Cross-site scripting (XSS) vulnerability in userupload.php in OlateDownload 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the description_small paramete…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5145

Published Oct 5, 2006

Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1