Sql-ledger

Sql-ledger

16 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Published 20.03.2007 22:19:00
  • Last modified 09.04.2025 00:30:58

Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against directory traversal attacks, which allows remote attackers to run arbitrary executables and bypass authenticatio...

  • EPSS 0.83%
  • Published 13.03.2007 19:19:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authentication via unknown vectors that prevents a password check from occurring.

  • EPSS 0.79%
  • Published 13.03.2007 19:19:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error fun...

  • EPSS 6.81%
  • Published 07.03.2007 21:19:00
  • Last modified 09.04.2025 00:30:58

Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which ...

  • EPSS 1.83%
  • Published 02.02.2007 21:28:00
  • Last modified 09.04.2025 00:30:58

The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.

Exploit
  • EPSS 1.64%
  • Published 31.08.2006 01:04:00
  • Last modified 03.04.2025 01:03:51

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie...