Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-0667

Опубликовано: 02 фев. 2007
Источник: debian
EPSS Низкий

Описание

The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sql-ledgerunfixedpackage
sql-ledgerno-dsaetchpackage

Примечания

  • It's documented behaviour that SQL-Ledger should only be run in an

  • authenticated HTTP zone and without untrusted users

  • sql-ledger 2.6.22-2 adds a note to README.Debian that sql-ledger

  • is not secure with untrusted users.

EPSS

Процентиль: 81%
0.01651
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.

nvd
больше 18 лет назад

The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.

github
больше 3 лет назад

The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.

EPSS

Процентиль: 81%
0.01651
Низкий