Vulnerabilities > CVE-2007-1329 - Directory Traversal vulnerability in LedgerSMB

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
ledgersmb
sql-ledger
critical

Summary

Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.

Vulnerable Configurations

Part Description Count
Application
Ledgersmb
1
Application
Sql-Ledger
1