Vulnerability Details CVE-2007-0667
The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.2%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2007-0667
-
cpe:2.3:a:ledgersmb:ledgersmb:1.0.0
-
cpe:2.3:a:ledgersmb:ledgersmb:1.1
-
cpe:2.3:a:ledgersmb:ledgersmb:1.1.1
-
cpe:2.3:a:sql-ledger:sql-ledger:2.4.7
-
cpe:2.3:a:sql-ledger:sql-ledger:2.6.17
-
cpe:2.3:a:sql-ledger:sql-ledger:2.6.18
-
cpe:2.3:a:sql-ledger:sql-ledger:2.6.19
-
cpe:2.3:a:sql-ledger:sql-ledger:2.6.21
-
cpe:2.3:a:sql-ledger:sql-ledger:2.6.25