7.5
CVSSv2

CVE-2006-5145

Published: 05/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote malicious users to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query parameter in search.php.

Vulnerable Product Search on Vulmon Subscribe to Product

olate olatedownload 3.4.0

Exploits

source: wwwsecurityfocuscom/bid/20278/info OlateDownload is prone to multiple input-validation vulnerabilities, including HTML-injection and SQL-injection issues, because the application fails to properly sanitize user-supplied input A successful exploit of these vulnerabilities could allow an attacker to inject hostile HTML and scri ...
source: wwwsecurityfocuscom/bid/20278/info OlateDownload is prone to multiple input-validation vulnerabilities, including HTML-injection and SQL-injection issues, because the application fails to properly sanitize user-supplied input A successful exploit of these vulnerabilities could allow an attacker to inject hostile HTML and script ...