CVE Vulnerabilities

CVE-2007-3907

Published: Jul 19, 2007 | Modified: Oct 15, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action.

Affected Software

Name Vendor Start Version End Version
Ledgersmb Ledgersmb 1.2.0 (including) 1.2.0 (including)
Ledgersmb Ledgersmb 1.2.1 (including) 1.2.1 (including)
Ledgersmb Ledgersmb 1.2.2 (including) 1.2.2 (including)
Ledgersmb Ledgersmb 1.2.3 (including) 1.2.3 (including)
Ledgersmb Ledgersmb 1.2.4 (including) 1.2.4 (including)
Ledgersmb Ledgersmb 1.2.5 (including) 1.2.5 (including)
Ledgersmb Ledgersmb 1.2.6 (including) 1.2.6 (including)

References