CVE Tools

Olate

7 CVEs tracked since 2006. Since Oct 2006, none of them reached CISA KEV.

Olate CVEs per month

Oct 2006 to Aug 2007. Point at a month, or focus the strip and use the arrow keys.
Olate CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2006-1020
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-0850

Products

The products that kept showing up in Olate's monthly top three, with their CVEs summed over those months.

  1. Olatedownload72 months

Latest CVEs

The 8 most recently published vulnerabilities affecting Olate.

  1. CVE-2007-4541Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the PHP_SELF variable in modules/core/uim.php ...4.3
  2. CVE-2007-4540Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute arbitrary SQL commands via the (1) HTTP_REFERER or (2) HTTP_USER_AGENT HTTP hea...7.5
  3. CVE-2007-4454Eval injection vulnerability in environment.php in Olate Download (od) 3.4.1 allows context-dependent attackers to execute arbitrary code via a crafted version string, as referenced by the (1) PDO:...6.8
  4. CVE-2007-4421SQL injection vulnerability in Admin.php in Olate Download (od) 3.4.1 allows remote attackers to execute arbitrary SQL commands via an OD3_AutoLogin cookie.9.3
  5. CVE-2007-4419Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers ...9.3
  6. CVE-2006-5144Cross-site scripting (XSS) vulnerability in userupload.php in OlateDownload 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the description_small parameter.6.8
  7. CVE-2006-5145Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query parameter in search...7.5
  8. CVE-2006-3342Cross-site scripting (XSS) vulnerability in index.php in Arctic 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search cmd.2.6

The record

Peak rank
#20 in Aug 2007
Busiest month shown
Aug 2007, 5 CVEs
Months with a KEV entry
0 since Oct 2006
Monthly snapshots
2 since 2006
Olate's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store