>> SQL-Ledger Login Form Remote Directory Traversal and Code Execution Vulnerability
Title : SQL-Ledger Login Form Remote Directory Traversal and Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-1025 CVE ID : CVE-2007-1540 - CVE-2007-1541
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-03-20
Technical Description
A vulnerability has been identified in SQL-Ledger, which could be exploited by attackers to execute arbitrary commands. This issue is due to an unspecified input validation error related to the login form, which could be exploited by malicious people to conduct directory traversal and code execution attacks.