Vulnerabilities > Olate > Olatedownload > 3.4.1

DATE CVE VULNERABILITY TITLE RISK
2007-08-21 CVE-2007-4454 Unspecified vulnerability in Olate Olatedownload 3.4.1
Eval injection vulnerability in environment.php in Olate Download (od) 3.4.1 allows context-dependent attackers to execute arbitrary code via a crafted version string, as referenced by the (1) PDO::ATTR_SERVER_VERSION or (2) PDO::ATTR_CLIENT_VERSION attribute.
network
olate
6.8
2007-08-18 CVE-2007-4421 SQL Injection vulnerability in Olate Olatedownload 3.4.1
SQL injection vulnerability in Admin.php in Olate Download (od) 3.4.1 allows remote attackers to execute arbitrary SQL commands via an OD3_AutoLogin cookie.
network
olate
critical
9.3
2007-08-18 CVE-2007-4419 Improper Authentication vulnerability in Olate Olatedownload 3.4.1
Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.
network
olate CWE-287
critical
9.3