sql-ledger kayıtları
sql-ledger üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %31,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-16 Configuration2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-287 Improper Authentication1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2007-1329İstismar yok | Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, ledgersmb · ledgersmb | Kritik10,0 | — | %5,2 | 7 Mar 2007 |
37İzleyin | CVE-2007-1437İstismar yok | Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypledgersmb · ledgersmb | Kritik9,0 | — | %3,4 | 13 Mar 2007 |
32İzleyin | CVE-2008-4077İstismar yok | The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of servledgersmb · ledgersmb · CWE-400 | Yüksek7,8 | — | %2,8 | 15 Eyl 2008 |
31İzleyin | CVE-2007-1923İstismar yok | (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remoledgersmb · ledgersmb | Yüksek7,5 | — | %2,6 | 10 Nis 2007 |
31İzleyin | CVE-2006-4244İstismar yok | SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of thesql-ledger · sql-ledger · CWE-287 | Yüksek7,5 | — | %1,9 | 30 Ağu 2006 |
31İzleyin | CVE-2007-1436İstismar yok | Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authenticatioledgersmb · ledgersmb | Yüksek7,5 | — | %1,8 | 13 Mar 2007 |
30İzleyin | CVE-2007-1541İstismar yok | Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against disql-ledger · sql-ledger | Yüksek7,5 | — | %1,6 | 20 Mar 2007 |
30İzleyin | CVE-2009-4402İstismar yok | The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbisql-ledger · sql-ledger · CWE-16 | Yüksek7,5 | — | %1,4 | 23 Ara 2009 |
27İzleyin | CVE-2007-0667İstismar yok | The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary coledgersmb · ledgersmb | Orta6,5 | — | %1,9 | 2 Şub 2007 |
27İzleyin | CVE-2009-3580İstismar yok | Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrsql-ledger · sql-ledger · CWE-352 | Orta6,8 | — | %0,6 | 23 Ara 2009 |
26İzleyin | CVE-2008-4078İstismar yok | SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier alloledgersmb · ledgersmb · CWE-89 | Orta6,5 | — | %1,6 | 15 Eyl 2008 |
26İzleyin | CVE-2009-3582İstismar yok | Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary Ssql-ledger · sql-ledger · CWE-89 | Orta6,5 | — | %0,9 | 23 Ara 2009 |
20İzleyin | CVE-2009-3583İstismar yok | Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrarysql-ledger · sql-ledger · CWE-22 | Orta5,1 | — | %1,3 | 23 Ara 2009 |
20İzleyin | CVE-2009-3584İstismar yok | SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capsql-ledger · sql-ledger · CWE-16 | Orta5,0 | — | %1,2 | 23 Ara 2009 |
18İzleyin | CVE-2007-1540Kavram kanıtı | Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to ledgersmb · ledgersmb | Orta4,3 | — | %4,9 | 20 Mar 2007 |
14İzleyin | CVE-2009-3581İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or sql-ledger · sql-ledger · CWE-79 | Düşük3,5 | — | %0,9 | 23 Ara 2009 |
- CVE-2007-132942Planlayın
Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files,
KritikCVSS 10,0İstismar yokEPSS %5ledgersmb · ledgersmb7 Mar 2007
- CVE-2007-143737İzleyin
Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly byp
KritikCVSS 9,0İstismar yokEPSS %3ledgersmb · ledgersmb13 Mar 2007
- CVE-2008-407732İzleyin
The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of serv
YüksekCVSS 7,8İstismar yokEPSS %3ledgersmb · ledgersmb15 Eyl 2008
- CVE-2007-192331İzleyin
(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remo
YüksekCVSS 7,5İstismar yokEPSS %3ledgersmb · ledgersmb10 Nis 2007
- CVE-2006-424431İzleyin
SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the
YüksekCVSS 7,5İstismar yokEPSS %2sql-ledger · sql-ledger30 Ağu 2006
- CVE-2007-143631İzleyin
Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authenticatio
YüksekCVSS 7,5İstismar yokEPSS %2ledgersmb · ledgersmb13 Mar 2007
- CVE-2007-154130İzleyin
Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against di
YüksekCVSS 7,5İstismar yokEPSS %2sql-ledger · sql-ledger20 Mar 2007
- CVE-2009-440230İzleyin
The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbi
YüksekCVSS 7,5İstismar yokEPSS %1sql-ledger · sql-ledger23 Ara 2009
- CVE-2007-066727İzleyin
The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary co
OrtaCVSS 6,5İstismar yokEPSS %2ledgersmb · ledgersmb2 Şub 2007
- CVE-2009-358027İzleyin
Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitr
OrtaCVSS 6,8İstismar yokEPSS %1sql-ledger · sql-ledger23 Ara 2009
- CVE-2008-407826İzleyin
SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allo
OrtaCVSS 6,5İstismar yokEPSS %2ledgersmb · ledgersmb15 Eyl 2008
- CVE-2009-358226İzleyin
Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary S
OrtaCVSS 6,5İstismar yokEPSS %1sql-ledger · sql-ledger23 Ara 2009
- CVE-2009-358320İzleyin
Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary
OrtaCVSS 5,1İstismar yokEPSS %1sql-ledger · sql-ledger23 Ara 2009
- CVE-2009-358420İzleyin
SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to cap
OrtaCVSS 5,0İstismar yokEPSS %1sql-ledger · sql-ledger23 Ara 2009
- CVE-2007-154018İzleyin
Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to
OrtaCVSS 4,3Kavram kanıtıEPSS %5ledgersmb · ledgersmb20 Mar 2007
- CVE-2009-358114İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or
DüşükCVSS 3,5İstismar yokEPSS %1sql-ledger · sql-ledger23 Ara 2009