Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-4731. PoCs published by Chris Murtagh.
AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in SQL-Ledger and LedgerSMB, allowing arbitrary file inclusion via the 'terminal' parameter. No actual exploit code is present, only a description and example URL.
Description
Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash).
Exploits (1)
The provided text describes a directory traversal vulnerability in SQL-Ledger and LedgerSMB, allowing arbitrary file inclusion via the 'terminal' parameter. No actual exploit code is present, only a description and example URL.