Known Vulnerabilities for products from Ledgersmb
Listed below are 17 of the newest known vulnerabilities associated with the vendor "Ledgersmb".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-3882 json | LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSM... | 6.8 - MEDIUM | 2021-10-14 | 2024-02-05 |
| CVE-2021-3731 json | LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allo... | 4.7 - MEDIUM | 2021-08-23 | 2021-08-27 |
| CVE-2021-3694 json | LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an auth... | 9.6 - CRITICAL | 2021-08-23 | 2021-08-27 |
| CVE-2021-3693 json | LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an... | 9.6 - CRITICAL | 2021-08-23 | 2021-08-27 |
| CVE-2018-9246 json | The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or e... | 9.8 - CRITICAL | 2018-06-08 | 2018-08-01 |
| CVE-2008-4078 json | SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 a... | Not Provided | 2008-09-15 | 2026-04-23 |
| CVE-2008-4077 json | The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a... | Not Provided | 2008-09-15 | 2026-04-23 |
| CVE-2007-5372 json | Multiple SQL injection vulnerabilities in (a) LedgerSMB 1.0.0 through 1.2.7 and (b) DWS Systems SQL-Ledger 2.x allow remote a... | Not Provided | 2007-10-11 | 2026-04-23 |
| CVE-2007-3907 json | Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and p... | Not Provided | 2007-07-19 | 2026-04-23 |
| CVE-2007-1923 json | (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, wh... | Not Provided | 2007-04-10 | 2026-04-23 |
| CVE-2007-1540 json | Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remot... | Not Provided | 2007-03-20 | 2026-04-23 |
| CVE-2007-1437 json | Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files a... | Not Provided | 2007-03-13 | 2026-04-23 |
| CVE-2007-1436 json | Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypas... | Not Provided | 2007-03-13 | 2026-04-23 |
| CVE-2007-1329 json | Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite ar... | Not Provided | 2007-03-07 | 2026-04-23 |
| CVE-2007-0667 json | The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execu... | Not Provided | 2007-02-02 | 2026-04-23 |
| CVE-2006-5589 json | Multiple SQL injection vulnerabilities in LedgerSMB (LSMB) 1.1.0 and earlier allow remote attackers to execute arbitrary SQL ... | Not Provided | 2006-10-27 | 2026-04-23 |
| CVE-2006-4731 json | Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerS... | 5 - MEDIUM | 2006-09-13 | 2023-11-07 |