Записи sql-ledger
16 опубликованных записей вендора sql-ledger.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 31,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-16 Configuration2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-287 Improper Authentication1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2007-1329Эксплойта нет | Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, ledgersmb · ledgersmb | Критическая10,0 | — | 5,2 % | 7 мар. 2007 г. |
37Наблюдать | CVE-2007-1437Эксплойта нет | Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypledgersmb · ledgersmb | Критическая9,0 | — | 3,4 % | 13 мар. 2007 г. |
32Наблюдать | CVE-2008-4077Эксплойта нет | The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of servledgersmb · ledgersmb · CWE-400 | Высокая7,8 | — | 2,8 % | 15 сент. 2008 г. |
31Наблюдать | CVE-2007-1923Эксплойта нет | (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remoledgersmb · ledgersmb | Высокая7,5 | — | 2,6 % | 10 апр. 2007 г. |
31Наблюдать | CVE-2006-4244Эксплойта нет | SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of thesql-ledger · sql-ledger · CWE-287 | Высокая7,5 | — | 1,9 % | 30 авг. 2006 г. |
31Наблюдать | CVE-2007-1436Эксплойта нет | Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authenticatioledgersmb · ledgersmb | Высокая7,5 | — | 1,8 % | 13 мар. 2007 г. |
30Наблюдать | CVE-2007-1541Эксплойта нет | Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against disql-ledger · sql-ledger | Высокая7,5 | — | 1,6 % | 20 мар. 2007 г. |
30Наблюдать | CVE-2009-4402Эксплойта нет | The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbisql-ledger · sql-ledger · CWE-16 | Высокая7,5 | — | 1,4 % | 23 дек. 2009 г. |
27Наблюдать | CVE-2007-0667Эксплойта нет | The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary coledgersmb · ledgersmb | Средняя6,5 | — | 1,9 % | 2 февр. 2007 г. |
27Наблюдать | CVE-2009-3580Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrsql-ledger · sql-ledger · CWE-352 | Средняя6,8 | — | 0,6 % | 23 дек. 2009 г. |
26Наблюдать | CVE-2008-4078Эксплойта нет | SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier alloledgersmb · ledgersmb · CWE-89 | Средняя6,5 | — | 1,6 % | 15 сент. 2008 г. |
26Наблюдать | CVE-2009-3582Эксплойта нет | Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary Ssql-ledger · sql-ledger · CWE-89 | Средняя6,5 | — | 0,9 % | 23 дек. 2009 г. |
20Наблюдать | CVE-2009-3583Эксплойта нет | Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrarysql-ledger · sql-ledger · CWE-22 | Средняя5,1 | — | 1,3 % | 23 дек. 2009 г. |
20Наблюдать | CVE-2009-3584Эксплойта нет | SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capsql-ledger · sql-ledger · CWE-16 | Средняя5,0 | — | 1,2 % | 23 дек. 2009 г. |
18Наблюдать | CVE-2007-1540Proof of concept | Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to ledgersmb · ledgersmb | Средняя4,3 | — | 4,9 % | 20 мар. 2007 г. |
14Наблюдать | CVE-2009-3581Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or sql-ledger · sql-ledger · CWE-79 | Низкая3,5 | — | 0,9 % | 23 дек. 2009 г. |
- CVE-2007-132942В плане
Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files,
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %ledgersmb · ledgersmb7 мар. 2007 г.
- CVE-2007-143737Наблюдать
Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly byp
КритическаяCVSS 9,0Эксплойта нетEPSS 3 %ledgersmb · ledgersmb13 мар. 2007 г.
- CVE-2008-407732Наблюдать
The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of serv
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %ledgersmb · ledgersmb15 сент. 2008 г.
- CVE-2007-192331Наблюдать
(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remo
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %ledgersmb · ledgersmb10 апр. 2007 г.
- CVE-2006-424431Наблюдать
SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sql-ledger · sql-ledger30 авг. 2006 г.
- CVE-2007-143631Наблюдать
Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authenticatio
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ledgersmb · ledgersmb13 мар. 2007 г.
- CVE-2007-154130Наблюдать
Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against di
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sql-ledger · sql-ledger20 мар. 2007 г.
- CVE-2009-440230Наблюдать
The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sql-ledger · sql-ledger23 дек. 2009 г.
- CVE-2007-066727Наблюдать
The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary co
СредняяCVSS 6,5Эксплойта нетEPSS 2 %ledgersmb · ledgersmb2 февр. 2007 г.
- CVE-2009-358027Наблюдать
Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitr
СредняяCVSS 6,8Эксплойта нетEPSS 1 %sql-ledger · sql-ledger23 дек. 2009 г.
- CVE-2008-407826Наблюдать
SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allo
СредняяCVSS 6,5Эксплойта нетEPSS 2 %ledgersmb · ledgersmb15 сент. 2008 г.
- CVE-2009-358226Наблюдать
Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary S
СредняяCVSS 6,5Эксплойта нетEPSS 1 %sql-ledger · sql-ledger23 дек. 2009 г.
- CVE-2009-358320Наблюдать
Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary
СредняяCVSS 5,1Эксплойта нетEPSS 1 %sql-ledger · sql-ledger23 дек. 2009 г.
- CVE-2009-358420Наблюдать
SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to cap
СредняяCVSS 5,0Эксплойта нетEPSS 1 %sql-ledger · sql-ledger23 дек. 2009 г.
- CVE-2007-154018Наблюдать
Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to
СредняяCVSS 4,3Proof of conceptEPSS 5 %ledgersmb · ledgersmb20 мар. 2007 г.
- CVE-2009-358114Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or
НизкаяCVSS 3,5Эксплойта нетEPSS 1 %sql-ledger · sql-ledger23 дек. 2009 г.