AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-3907

HIGH · CVSS 10 EPSS 2.96%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-07-19 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2007-3907
Severity
HIGH
CVSS
10
EPSS
2.96%

Original NVD Description

Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action.