CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an encoded LF followed by a malicious target line.
| Software | From | Fixed in |
|---|---|---|
| akamai / download_manager | 2.0.4.4 | 2.0.4.4.x |
| akamai / download_manager | 2.2.0.0 | 2.2.0.0.x |
| akamai / download_manager | 2.2.1.0 | 2.2.1.0.x |
| akamai / download_manager | - | 2.2.3.5.x |