Back to search
CVE-2007-4541
Published: Aug 27, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the PHP_SELF variable in modules/core/uim.php and (2) [url] tags in a comment in modules/core/fldm.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
olatedownload-fldm-xss(36197)
vdb-entry
x_refsource_XF
25412
vdb-entry
x_refsource_BID
39711
vdb-entry
x_refsource_OSVDB
20070822 Olate Download 3.4.2~modules/core/uim.php~XSS
mailing-list
x_refsource_BUGTRAQ
39710
vdb-entry
x_refsource_OSVDB
26565
third-party-advisory
x_refsource_SECUNIA
3076
third-party-advisory
x_refsource_SREASON
olatedownload-files-xss(36196)
vdb-entry
x_refsource_XF
20070822 Olate Download 3.4.2~modules/core/fldm.php~comments tag [url] XSS
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now