5

CVE-2006-4731

Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dws Systems Inc.Sql-ledger Version2.2.0
Dws Systems Inc.Sql-ledger Version2.2.1
Dws Systems Inc.Sql-ledger Version2.2.2
Dws Systems Inc.Sql-ledger Version2.2.3
Dws Systems Inc.Sql-ledger Version2.2.4
Dws Systems Inc.Sql-ledger Version2.2.5
Dws Systems Inc.Sql-ledger Version2.2.6
Dws Systems Inc.Sql-ledger Version2.2.7
Dws Systems Inc.Sql-ledger Version2.4.0
Dws Systems Inc.Sql-ledger Version2.4.1
Dws Systems Inc.Sql-ledger Version2.4.2
Dws Systems Inc.Sql-ledger Version2.4.3
Dws Systems Inc.Sql-ledger Version2.4.4
Dws Systems Inc.Sql-ledger Version2.4.5
Dws Systems Inc.Sql-ledger Version2.4.6
Dws Systems Inc.Sql-ledger Version2.4.7
Dws Systems Inc.Sql-ledger Version2.4.8
Dws Systems Inc.Sql-ledger Version2.4.9
Dws Systems Inc.Sql-ledger Version2.4.10
Dws Systems Inc.Sql-ledger Version2.4.11
Dws Systems Inc.Sql-ledger Version2.4.12
Dws Systems Inc.Sql-ledger Version2.4.13
Dws Systems Inc.Sql-ledger Version2.4.14
Dws Systems Inc.Sql-ledger Version2.4.15
Dws Systems Inc.Sql-ledger Version2.4.16
Dws Systems Inc.Sql-ledger Version2.6.1
Dws Systems Inc.Sql-ledger Version2.6.2
Dws Systems Inc.Sql-ledger Version2.6.3
Dws Systems Inc.Sql-ledger Version2.6.4
Dws Systems Inc.Sql-ledger Version2.6.5
Dws Systems Inc.Sql-ledger Version2.6.6
Dws Systems Inc.Sql-ledger Version2.6.7
Dws Systems Inc.Sql-ledger Version2.6.8
Dws Systems Inc.Sql-ledger Version2.6.9
Dws Systems Inc.Sql-ledger Version2.6.10
Dws Systems Inc.Sql-ledger Version2.6.11
Dws Systems Inc.Sql-ledger Version2.6.12
Dws Systems Inc.Sql-ledger Version2.6.13
Dws Systems Inc.Sql-ledger Version2.6.14
Dws Systems Inc.Sql-ledger Version2.6.15
Dws Systems Inc.Sql-ledger Version2.6.16
Dws Systems Inc.Sql-ledger Version2.6.17
Dws Systems Inc.Sql-ledger Version2.6.18
LedgersmbLedgersmb Version <= 1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.2% 0.951
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N