Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-1329

Опубликовано: 07 мар. 2007
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10

Описание

Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

dapper

ignored

end of life
devel

DNE

disco

DNE

edgy

ignored

end of life, was needed
eoan

DNE

esm-apps/xenial

ignored

see notes
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]

Показывать по

Ссылки на источники

EPSS

Процентиль: 91%
0.07066
Низкий

10 Critical

CVSS2

Связанные уязвимости

nvd
больше 18 лет назад

Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.

debian
больше 18 лет назад

Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before ...

github
больше 3 лет назад

Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.

EPSS

Процентиль: 91%
0.07066
Низкий

10 Critical

CVSS2