Vulnerabilities > CVE-2007-1437 - Remote Security vulnerability in LedgerSMB

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
ledgersmb
sql-ledger
critical

Summary

Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error function that returns from execution.

Vulnerable Configurations

Part Description Count
Application
Ledgersmb
3
Application
Sql-Ledger
1