Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sql Ledger HIGH 7.5
CVE-2009-4402

The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbitrary pas…

Mitigation only
Fix from $1,950 2009-12-23
Sql Ledger MEDIUM 6.8
CVE-2009-3580

Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrary users…

Mitigation only
Fix from $1,600 2009-12-23
Sql Ledger MEDIUM 6.5
CVE-2009-3582

Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary SQL comman…

Mitigation only
Fix from $1,600 2009-12-23
Sql Ledger MEDIUM 5.1
CVE-2009-3583

Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary local fi…

Mitigation only
Fix from $1,600 2009-12-23
Sql Ledger MEDIUM 5.0
CVE-2009-3584

SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this…

Mitigation only
Fix from $1,600 2009-12-23
Sql Ledger HIGH 7.5
CVE-2007-1541

Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against directory t…

Mitigation only
Fix from $1,950 2007-03-20
Sql Ledger HIGH 7.5
CVE-2006-4244

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessioni…

No fix yet
Fix from $1,950 2006-08-31