CVE-2007-3907
Last modified
CVE-2007-3907 is a vulnerability of currently unknown severity. Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action.. EPSS estimates a 2.96% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ledgersmb | Ledgersmb | 1.2.0 |
| Ledgersmb | Ledgersmb | 1.2.1 |
| Ledgersmb | Ledgersmb | 1.2.2 |
| Ledgersmb | Ledgersmb | 1.2.3 |
| Ledgersmb | Ledgersmb | 1.2.4 |
| Ledgersmb | Ledgersmb | 1.2.5 |
| Ledgersmb | Ledgersmb | 1.2.6 |
References
- http://secunia.com/advisories/26121Vendor Advisory
- http://secunia.com/advisories/26121Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3907?
How severe is CVE-2007-3907?
How do I fix CVE-2007-3907?
Are you affected by CVE-2007-3907?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
