Skip to content
Noroxi

sql-ledger records

16 published records for vendor sql-ledger.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
31.3%
Median publish → KEV
No record has entered KEV

All records

16 records
  • Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files,

    CriticalCVSS 10.0No exploitEPSS 5%

    ledgersmb · ledgersmbMar 7, 2007

  • CVE-2007-1437
    37Monitor

    Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly byp

    CriticalCVSS 9.0No exploitEPSS 3%

    ledgersmb · ledgersmbMar 13, 2007

  • CVE-2008-4077
    32Monitor

    The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of serv

    HighCVSS 7.8No exploitEPSS 3%

    ledgersmb · ledgersmbSep 15, 2008

  • CVE-2007-1923
    31Monitor

    (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remo

    HighCVSS 7.5No exploitEPSS 3%

    ledgersmb · ledgersmbApr 10, 2007

  • CVE-2006-4244
    31Monitor

    SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the

    HighCVSS 7.5No exploitEPSS 2%

    sql-ledger · sql-ledgerAug 30, 2006

  • CVE-2007-1436
    31Monitor

    Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authenticatio

    HighCVSS 7.5No exploitEPSS 2%

    ledgersmb · ledgersmbMar 13, 2007

  • CVE-2007-1541
    30Monitor

    Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against di

    HighCVSS 7.5No exploitEPSS 2%

    sql-ledger · sql-ledgerMar 20, 2007

  • CVE-2009-4402
    30Monitor

    The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbi

    HighCVSS 7.5No exploitEPSS 1%

    sql-ledger · sql-ledgerDec 23, 2009

  • CVE-2007-0667
    27Monitor

    The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary co

    MediumCVSS 6.5No exploitEPSS 2%

    ledgersmb · ledgersmbFeb 2, 2007

  • CVE-2009-3580
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitr

    MediumCVSS 6.8No exploitEPSS 1%

    sql-ledger · sql-ledgerDec 23, 2009

  • CVE-2008-4078
    26Monitor

    SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allo

    MediumCVSS 6.5No exploitEPSS 2%

    ledgersmb · ledgersmbSep 15, 2008

  • CVE-2009-3582
    26Monitor

    Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary S

    MediumCVSS 6.5No exploitEPSS 1%

    sql-ledger · sql-ledgerDec 23, 2009

  • CVE-2009-3583
    20Monitor

    Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary

    MediumCVSS 5.1No exploitEPSS 1%

    sql-ledger · sql-ledgerDec 23, 2009

  • CVE-2009-3584
    20Monitor

    SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to cap

    MediumCVSS 5.0No exploitEPSS 1%

    sql-ledger · sql-ledgerDec 23, 2009

  • CVE-2007-1540
    18Monitor

    Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to

    MediumCVSS 4.3Proof of conceptEPSS 5%

    ledgersmb · ledgersmbMar 20, 2007

  • CVE-2009-3581
    14Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or

    LowCVSS 3.5No exploitEPSS 1%

    sql-ledger · sql-ledgerDec 23, 2009