CVE-2007-1541
- EPSS 0.37%
- Veröffentlicht 20.03.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against directory traversal attacks, which allows remote attackers to run arbitrary executables and bypass authenticatio...
CVE-2007-1436
- EPSS 0.83%
- Veröffentlicht 13.03.2007 19:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authentication via unknown vectors that prevents a password check from occurring.
- EPSS 0.79%
- Veröffentlicht 13.03.2007 19:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error fun...
- EPSS 6.81%
- Veröffentlicht 07.03.2007 21:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which ...
CVE-2007-0667
- EPSS 1.83%
- Veröffentlicht 02.02.2007 21:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.
CVE-2006-4244
- EPSS 1.64%
- Veröffentlicht 31.08.2006 01:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie...