CVE-2006-4731

UnknownEPSS 5.73%

Last modified

CVE-2006-4731 is a vulnerability of currently unknown severity. Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash).. EPSS estimates a 5.73% chance of exploitation in the next 30 days.

Description

Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash).

Metrics

EPSS Probability
5.73%

92.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Dws Systems Inc.Sql-Ledger2.2.0
Dws Systems Inc.Sql-Ledger2.2.1
Dws Systems Inc.Sql-Ledger2.2.2
Dws Systems Inc.Sql-Ledger2.2.3
Dws Systems Inc.Sql-Ledger2.2.4
Dws Systems Inc.Sql-Ledger2.2.5
Dws Systems Inc.Sql-Ledger2.2.6
Dws Systems Inc.Sql-Ledger2.2.7
Dws Systems Inc.Sql-Ledger2.4.0
Dws Systems Inc.Sql-Ledger2.4.1
Dws Systems Inc.Sql-Ledger2.4.2
Dws Systems Inc.Sql-Ledger2.4.3
Dws Systems Inc.Sql-Ledger2.4.4
Dws Systems Inc.Sql-Ledger2.4.5
Dws Systems Inc.Sql-Ledger2.4.6
Dws Systems Inc.Sql-Ledger2.4.7
Dws Systems Inc.Sql-Ledger2.4.8
Dws Systems Inc.Sql-Ledger2.4.9
Dws Systems Inc.Sql-Ledger2.4.10
Dws Systems Inc.Sql-Ledger2.4.11
Dws Systems Inc.Sql-Ledger2.4.12
Dws Systems Inc.Sql-Ledger2.4.13
Dws Systems Inc.Sql-Ledger2.4.14
Dws Systems Inc.Sql-Ledger2.4.15
Dws Systems Inc.Sql-Ledger2.4.16
Dws Systems Inc.Sql-Ledger2.6.1
Dws Systems Inc.Sql-Ledger2.6.2
Dws Systems Inc.Sql-Ledger2.6.3
Dws Systems Inc.Sql-Ledger2.6.4
Dws Systems Inc.Sql-Ledger2.6.5
Dws Systems Inc.Sql-Ledger2.6.6
Dws Systems Inc.Sql-Ledger2.6.7
Dws Systems Inc.Sql-Ledger2.6.8
Dws Systems Inc.Sql-Ledger2.6.9
Dws Systems Inc.Sql-Ledger2.6.10
Dws Systems Inc.Sql-Ledger2.6.11
Dws Systems Inc.Sql-Ledger2.6.12
Dws Systems Inc.Sql-Ledger2.6.13
Dws Systems Inc.Sql-Ledger2.6.14
Dws Systems Inc.Sql-Ledger2.6.15
Dws Systems Inc.Sql-Ledger2.6.16
Dws Systems Inc.Sql-Ledger2.6.17
Dws Systems Inc.Sql-Ledger2.6.18
LedgersmbLedgersmb<= 1.0.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-4731?
Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash).
How severe is CVE-2006-4731?
Severity scoring for CVE-2006-4731 is pending analysis. The EPSS model estimates a 5.73% probability of exploitation in the next 30 days.
How do I fix CVE-2006-4731?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-4731?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST