CyberSec.Space Logo
CVEブラウザに戻る

CVE-2007-1329

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0110%
EPSS Percentile38.64th
Published2007年3月7日
Last Modified2026年4月23日

Vulnerability Description

Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.

Affected Platforms (CPE)

📦
Ledgersmb

Ledgersmb

<= 1.1.1
📦
Sql Ledger

Sql Ledger

= 2.6.25

References & Advisories

関連する脆弱性情報