CVE-2007-0667

The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.
Configurations

Configuration 1

cpe:2.3:a:sql-ledger:sql-ledger:2.4.7:*:*:*:*:*:*:*
cpe:2.3:a:sql-ledger:sql-ledger:2.6.19:*:*:*:*:*:*:*
cpe:2.3:a:sql-ledger:sql-ledger:2.6.17:*:*:*:*:*:*:*
cpe:2.3:a:sql-ledger:sql-ledger:2.6.25:*:*:*:*:*:*:*
cpe:2.3:a:sql-ledger:sql-ledger:2.6.18:*:*:*:*:*:*:*
cpe:2.3:a:ledgersmb:ledgersmb:*:*:*:*:*:*:*:*
cpe:2.3:a:sql-ledger:sql-ledger:2.6.21:*:*:*:*:*:*:*

Information

Published : 2007-02-02 09:28

Updated : 2018-10-16 04:33


NVD link : CVE-2007-0667

Mitre link : CVE-2007-0667

Products Affected
No products.