İçeriğe atla
Noroxi

sql-ledger kayıtları

sql-ledger üreticisine ait 16 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%31,3
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

16 kayıt
  • CVE-2007-1329
    42Planlayın

    Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files,

    KritikCVSS 10,0İstismar yokEPSS %5

    ledgersmb · ledgersmb7 Mar 2007

  • CVE-2007-1437
    37İzleyin

    Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly byp

    KritikCVSS 9,0İstismar yokEPSS %3

    ledgersmb · ledgersmb13 Mar 2007

  • CVE-2008-4077
    32İzleyin

    The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of serv

    YüksekCVSS 7,8İstismar yokEPSS %3

    ledgersmb · ledgersmb15 Eyl 2008

  • CVE-2007-1923
    31İzleyin

    (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remo

    YüksekCVSS 7,5İstismar yokEPSS %3

    ledgersmb · ledgersmb10 Nis 2007

  • CVE-2006-4244
    31İzleyin

    SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the

    YüksekCVSS 7,5İstismar yokEPSS %2

    sql-ledger · sql-ledger30 Ağu 2006

  • CVE-2007-1436
    31İzleyin

    Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authenticatio

    YüksekCVSS 7,5İstismar yokEPSS %2

    ledgersmb · ledgersmb13 Mar 2007

  • CVE-2007-1541
    30İzleyin

    Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against di

    YüksekCVSS 7,5İstismar yokEPSS %2

    sql-ledger · sql-ledger20 Mar 2007

  • CVE-2009-4402
    30İzleyin

    The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbi

    YüksekCVSS 7,5İstismar yokEPSS %1

    sql-ledger · sql-ledger23 Ara 2009

  • CVE-2007-0667
    27İzleyin

    The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary co

    OrtaCVSS 6,5İstismar yokEPSS %2

    ledgersmb · ledgersmb2 Şub 2007

  • CVE-2009-3580
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitr

    OrtaCVSS 6,8İstismar yokEPSS %1

    sql-ledger · sql-ledger23 Ara 2009

  • CVE-2008-4078
    26İzleyin

    SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allo

    OrtaCVSS 6,5İstismar yokEPSS %2

    ledgersmb · ledgersmb15 Eyl 2008

  • CVE-2009-3582
    26İzleyin

    Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary S

    OrtaCVSS 6,5İstismar yokEPSS %1

    sql-ledger · sql-ledger23 Ara 2009

  • CVE-2009-3583
    20İzleyin

    Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary

    OrtaCVSS 5,1İstismar yokEPSS %1

    sql-ledger · sql-ledger23 Ara 2009

  • CVE-2009-3584
    20İzleyin

    SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to cap

    OrtaCVSS 5,0İstismar yokEPSS %1

    sql-ledger · sql-ledger23 Ara 2009

  • CVE-2007-1540
    18İzleyin

    Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to

    OrtaCVSS 4,3Kavram kanıtıEPSS %5

    ledgersmb · ledgersmb20 Mar 2007

  • CVE-2009-3581
    14İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or

    DüşükCVSS 3,5İstismar yokEPSS %1

    sql-ledger · sql-ledger23 Ara 2009