Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2009-4402 The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbitrary pas… Sql Ledger Mitigation only Fix from $1,9502009-12-23 MEDIUM 6.8 CVE-2009-3580 Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrary users… Sql Ledger Mitigation only Fix from $1,6002009-12-23 MEDIUM 6.5 CVE-2009-3582 Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary SQL comman… Sql Ledger Mitigation only Fix from $1,6002009-12-23 MEDIUM 5.1 CVE-2009-3583 Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary local fi… Sql Ledger Mitigation only Fix from $1,6002009-12-23 MEDIUM 5.0 CVE-2009-3584 SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this… Sql Ledger Mitigation only Fix from $1,6002009-12-23 HIGH 7.5 CVE-2007-1541 Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against directory t… Sql Ledger Mitigation only Fix from $1,9502007-03-20 HIGH 7.5 CVE-2006-4244 SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessioni… Sql Ledger No fix yet Fix from $1,9502006-08-31