CVE-2009-3583
EPSS 0.33%
Description
Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the countrycode field.
How to fix CVE-2009-3583
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/sql-ledger—no fix listed
Is CVE-2009-3583 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0