sql-ledger records
16 published records for vendor sql-ledger.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 31.3%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-16 Configuration2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-287 Improper Authentication1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2007-1329No exploit | Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, ledgersmb · ledgersmb | Critical10.0 | — | 5.2% | Mar 7, 2007 |
37Monitor | CVE-2007-1437No exploit | Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypledgersmb · ledgersmb | Critical9.0 | — | 3.4% | Mar 13, 2007 |
32Monitor | CVE-2008-4077No exploit | The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of servledgersmb · ledgersmb · CWE-400 | High7.8 | — | 2.8% | Sep 15, 2008 |
31Monitor | CVE-2007-1923No exploit | (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remoledgersmb · ledgersmb | High7.5 | — | 2.6% | Apr 10, 2007 |
31Monitor | CVE-2006-4244No exploit | SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of thesql-ledger · sql-ledger · CWE-287 | High7.5 | — | 1.9% | Aug 30, 2006 |
31Monitor | CVE-2007-1436No exploit | Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authenticatioledgersmb · ledgersmb | High7.5 | — | 1.8% | Mar 13, 2007 |
30Monitor | CVE-2007-1541No exploit | Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against disql-ledger · sql-ledger | High7.5 | — | 1.6% | Mar 20, 2007 |
30Monitor | CVE-2009-4402No exploit | The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbisql-ledger · sql-ledger · CWE-16 | High7.5 | — | 1.4% | Dec 23, 2009 |
27Monitor | CVE-2007-0667No exploit | The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary coledgersmb · ledgersmb | Medium6.5 | — | 1.9% | Feb 2, 2007 |
27Monitor | CVE-2009-3580No exploit | Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrsql-ledger · sql-ledger · CWE-352 | Medium6.8 | — | 0.6% | Dec 23, 2009 |
26Monitor | CVE-2008-4078No exploit | SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier alloledgersmb · ledgersmb · CWE-89 | Medium6.5 | — | 1.6% | Sep 15, 2008 |
26Monitor | CVE-2009-3582No exploit | Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary Ssql-ledger · sql-ledger · CWE-89 | Medium6.5 | — | 0.9% | Dec 23, 2009 |
20Monitor | CVE-2009-3583No exploit | Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrarysql-ledger · sql-ledger · CWE-22 | Medium5.1 | — | 1.3% | Dec 23, 2009 |
20Monitor | CVE-2009-3584No exploit | SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capsql-ledger · sql-ledger · CWE-16 | Medium5.0 | — | 1.2% | Dec 23, 2009 |
18Monitor | CVE-2007-1540Proof of concept | Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to ledgersmb · ledgersmb | Medium4.3 | — | 4.9% | Mar 20, 2007 |
14Monitor | CVE-2009-3581No exploit | Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or sql-ledger · sql-ledger · CWE-79 | Low3.5 | — | 0.9% | Dec 23, 2009 |
- CVE-2007-132942Plan
Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files,
CriticalCVSS 10.0No exploitEPSS 5%ledgersmb · ledgersmbMar 7, 2007
- CVE-2007-143737Monitor
Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly byp
CriticalCVSS 9.0No exploitEPSS 3%ledgersmb · ledgersmbMar 13, 2007
- CVE-2008-407732Monitor
The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of serv
HighCVSS 7.8No exploitEPSS 3%ledgersmb · ledgersmbSep 15, 2008
- CVE-2007-192331Monitor
(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remo
HighCVSS 7.5No exploitEPSS 3%ledgersmb · ledgersmbApr 10, 2007
- CVE-2006-424431Monitor
SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the
HighCVSS 7.5No exploitEPSS 2%sql-ledger · sql-ledgerAug 30, 2006
- CVE-2007-143631Monitor
Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authenticatio
HighCVSS 7.5No exploitEPSS 2%ledgersmb · ledgersmbMar 13, 2007
- CVE-2007-154130Monitor
Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against di
HighCVSS 7.5No exploitEPSS 2%sql-ledger · sql-ledgerMar 20, 2007
- CVE-2009-440230Monitor
The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbi
HighCVSS 7.5No exploitEPSS 1%sql-ledger · sql-ledgerDec 23, 2009
- CVE-2007-066727Monitor
The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary co
MediumCVSS 6.5No exploitEPSS 2%ledgersmb · ledgersmbFeb 2, 2007
- CVE-2009-358027Monitor
Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitr
MediumCVSS 6.8No exploitEPSS 1%sql-ledger · sql-ledgerDec 23, 2009
- CVE-2008-407826Monitor
SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allo
MediumCVSS 6.5No exploitEPSS 2%ledgersmb · ledgersmbSep 15, 2008
- CVE-2009-358226Monitor
Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary S
MediumCVSS 6.5No exploitEPSS 1%sql-ledger · sql-ledgerDec 23, 2009
- CVE-2009-358320Monitor
Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary
MediumCVSS 5.1No exploitEPSS 1%sql-ledger · sql-ledgerDec 23, 2009
- CVE-2009-358420Monitor
SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to cap
MediumCVSS 5.0No exploitEPSS 1%sql-ledger · sql-ledgerDec 23, 2009
- CVE-2007-154018Monitor
Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to
MediumCVSS 4.3Proof of conceptEPSS 5%ledgersmb · ledgersmbMar 20, 2007
- CVE-2009-358114Monitor
Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or
LowCVSS 3.5No exploitEPSS 1%sql-ledger · sql-ledgerDec 23, 2009