Loading...
Loading...
Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence and trailing NULL (%00) in the login parameter. NOTE: this issue was reportedly addressed in SQL-Ledger 2.6.27, however third-party researchers claim that the file is still executed even though an error is generated.
March 20, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-1540
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.