Skip to content
Noroxi

olate records

8 published records for vendor olate.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
4
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

8 records
  • CVE-2007-4419
    38Monitor

    Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentic

    CriticalCVSS 9.3Proof of conceptEPSS 5%

    olate · olatedownloadAug 18, 2007

  • CVE-2007-4421
    38Monitor

    SQL injection vulnerability in Admin.php in Olate Download (od) 3.4.1 allows remote attackers to execute arbitrary SQL commands via an OD3_A

    CriticalCVSS 9.3No exploitEPSS 2%

    olate · olatedownloadAug 18, 2007

  • CVE-2007-4540
    30Monitor

    Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute arbitrary SQL commands

    HighCVSS 7.5No exploitEPSS 1%

    olate · olatedownloadAug 27, 2007

  • CVE-2006-5145
    30Monitor

    Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page para

    HighCVSS 7.5Proof of conceptEPSS 1%

    olate · olatedownloadOct 5, 2006

  • CVE-2007-4454
    28Monitor

    Eval injection vulnerability in environment.php in Olate Download (od) 3.4.1 allows context-dependent attackers to execute arbitrary code vi

    MediumCVSS 6.8No exploitEPSS 2%

    olate · olatedownloadAug 21, 2007

  • CVE-2006-5144
    27Monitor

    Cross-site scripting (XSS) vulnerability in userupload.php in OlateDownload 3.4.0 allows remote attackers to inject arbitrary web script or

    MediumCVSS 6.8No exploitEPSS 1%

    olate · olatedownloadOct 5, 2006

  • CVE-2007-4541
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitrary web script or HT

    MediumCVSS 4.3No exploitEPSS 1%

    olate · olatedownloadAug 27, 2007

  • CVE-2006-3342
    10Monitor

    Cross-site scripting (XSS) vulnerability in index.php in Arctic 1.0.2 and earlier allows remote attackers to inject arbitrary web script or

    LowCVSS 2.6No exploitEPSS 1%

    olate · arcticJul 3, 2006