CVE-2007-4419

Olate Download (od) 3.4.1 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-4419. PoCs published by imei.

AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in Olate Download by providing a crafted cookie value. The cookie bypasses authentication and grants administrative access to the application.

Description

Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.

Exploits (1)

exploitdb WORKING POC VERIFIED
by imei · textwebappsphp
https://www.exploit-db.com/exploits/30504

This exploit leverages an authentication bypass vulnerability in Olate Download by providing a crafted cookie value. The cookie bypasses authentication and grants administrative access to the application.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Olate Download versions prior to 3.4.2
No auth needed
Prerequisites: Access to the target application's cookie mechanism
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26533
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/36088
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25343
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/477223/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/476760/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3028
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/39714

Scores

EPSS 0.0483
EPSS Percentile 90.9%

Details

CWE
CWE-287
Status published
Products (1)
olate/olatedownload 3.4.1
Published Aug 18, 2007
Tracked Since Feb 18, 2026