CVE-2007-1329

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/03/2007
Last modified:
09/04/2025

Description

Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ledgersmb:ledgersmb:*:*:*:*:*:*:*:* 1.1.1 (including)
cpe:2.3:a:sql-ledger:sql-ledger:2.6.25:*:*:*:*:*:*:*