Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Loki_download_manager_catgory_version | Loki | 2.0 (including) | 2.0 (including) |