Security Advisory

CVE-2007-4419

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-08-18 21:00:00
Last updated 2024-08-07 14:53:56
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.