SQL Ledger is a modestly represented accounting and financial ledger software product with a footprint among more prominent vendors in the vulnerability landscape. The vendor's disclosures center on its single accounting application and reflect the input-handling and access-control exposure typical of web-based financial software; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sql Ledger over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1329HIGH Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) | Mar 7, 2007 | 10.0 | 26 | NO | NO |
CVE-2008-4077HIGH The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (resource exhaustion) via an HTTP PO | Sep 15, 2008 | 7.8 | 24 | NO | NO |
CVE-2007-1437HIGH Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authentic | Mar 13, 2007 | 9.0 | 23 | NO | NO |
CVE-2009-3580MEDIUM Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrary users for requests that change a pas | Dec 23, 2009 | 6.8 | 22 | NO | NO |
CVE-2007-1540MEDIUM Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitrary executables and bypass aut | Mar 20, 2007 | 4.3 | 22 | NO | YES |
CVE-2009-4402HIGH The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbitrary password to the admin interface. | Dec 23, 2009 | 7.5 | 21 | NO | NO |
CVE-2007-1923HIGH (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functi | Apr 10, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-1436HIGH Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authentication via unknown vectors that prevents a pa | Mar 13, 2007 | 7.5 | 20 | NO | NO |
CVE-2006-4244HIGH SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remot | Aug 31, 2006 | 7.5 | 20 | NO | NO |
CVE-2009-3582MEDIUM Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary SQL commands via the (1) id and possibly | Dec 23, 2009 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sql Ledger.
Media articles that mention a CVE ID that affects a product developed by Sql Ledger — matched by CVE ID, not by vendor name.