Перейти к содержимому
Noroxi

Записи sql-ledger

16 опубликованных записей вендора sql-ledger.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
31,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

16 записей
  • CVE-2007-1329
    42В плане

    Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files,

    КритическаяCVSS 10,0Эксплойта нетEPSS 5 %

    ledgersmb · ledgersmb7 мар. 2007 г.

  • CVE-2007-1437
    37Наблюдать

    Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly byp

    КритическаяCVSS 9,0Эксплойта нетEPSS 3 %

    ledgersmb · ledgersmb13 мар. 2007 г.

  • CVE-2008-4077
    32Наблюдать

    The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of serv

    ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %

    ledgersmb · ledgersmb15 сент. 2008 г.

  • CVE-2007-1923
    31Наблюдать

    (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remo

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    ledgersmb · ledgersmb10 апр. 2007 г.

  • CVE-2006-4244
    31Наблюдать

    SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    sql-ledger · sql-ledger30 авг. 2006 г.

  • CVE-2007-1436
    31Наблюдать

    Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authenticatio

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    ledgersmb · ledgersmb13 мар. 2007 г.

  • CVE-2007-1541
    30Наблюдать

    Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against di

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    sql-ledger · sql-ledger20 мар. 2007 г.

  • CVE-2009-4402
    30Наблюдать

    The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    sql-ledger · sql-ledger23 дек. 2009 г.

  • CVE-2007-0667
    27Наблюдать

    The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary co

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    ledgersmb · ledgersmb2 февр. 2007 г.

  • CVE-2009-3580
    27Наблюдать

    Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitr

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    sql-ledger · sql-ledger23 дек. 2009 г.

  • CVE-2008-4078
    26Наблюдать

    SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allo

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    ledgersmb · ledgersmb15 сент. 2008 г.

  • CVE-2009-3582
    26Наблюдать

    Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary S

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    sql-ledger · sql-ledger23 дек. 2009 г.

  • CVE-2009-3583
    20Наблюдать

    Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary

    СредняяCVSS 5,1Эксплойта нетEPSS 1 %

    sql-ledger · sql-ledger23 дек. 2009 г.

  • CVE-2009-3584
    20Наблюдать

    SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to cap

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    sql-ledger · sql-ledger23 дек. 2009 г.

  • CVE-2007-1540
    18Наблюдать

    Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to

    СредняяCVSS 4,3Proof of conceptEPSS 5 %

    ledgersmb · ledgersmb20 мар. 2007 г.

  • CVE-2009-3581
    14Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or

    НизкаяCVSS 3,5Эксплойта нетEPSS 1 %

    sql-ledger · sql-ledger23 дек. 2009 г.