CVE

Id
27897  
CVE No.
CVE-2007-4540  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute arbitrary SQL commands via the (1) HTTP_REFERER or (2) HTTP_USER_AGENT HTTP header.  
Phase
Assigned (20070827)  
Votes
None (candidate not yet proposed)  
Comments