CVE-2007-4419
Last modified
CVE-2007-4419 is a vulnerability of currently unknown severity. Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.. EPSS estimates a 4.83% chance of exploitation in the next 30 days.
Description
Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Olate | Olatedownload | 3.4.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4419?
How severe is CVE-2007-4419?
How do I fix CVE-2007-4419?
Are you affected by CVE-2007-4419?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
