SQL-Ledger Session ID Authentication Bypass Vulnerability
BID:19758
CVE-2006-4244 |Info
SQL-Ledger Session ID Authentication Bypass Vulnerability
| Bugtraq ID: | 19758 |
| Class: | Access Validation Error |
| CVE: |
CVE-2006-4244 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2006 12:00AM |
| Updated: | Jan 25 2007 04:26PM |
| Credit: | Chris Travers of Metatron Technology Consulting discovered this vulnerability. |
| Vulnerable: |
SQL-Ledger SQL-Ledger 2.6.17 SQL-Ledger SQL-Ledger 2.4.7 Debian Linux 3.1 |
| Not Vulnerable: | |
Discussion
SQL-Ledger Session ID Authentication Bypass Vulnerability
SQL-Ledger is prone to an authentication-bypass vulnerability.
A successful attack can allow unauthorized attackers to bypass authentication routines and gain access to the application as any logged-in user. An attacker may then carry out other attacks against the vulnerable computer or database.
SQL-Ledger is prone to an authentication-bypass vulnerability.
A successful attack can allow unauthorized attackers to bypass authentication routines and gain access to the application as any logged-in user. An attacker may then carry out other attacks against the vulnerable computer or database.
Exploit / POC
SQL-Ledger Session ID Authentication Bypass Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
SQL-Ledger Session ID Authentication Bypass Vulnerability
Solution:
Reports indicate that third-party patches are available to address this issue. Please see the reference section for more information. Symantec has not verified the integrity of these patches.
SQL-Ledger SQL-Ledger 2.4.7
Solution:
Reports indicate that third-party patches are available to address this issue. Please see the reference section for more information. Symantec has not verified the integrity of these patches.
SQL-Ledger SQL-Ledger 2.4.7
-
Debian sql-ledger_2.4.7-2sarge1_all.deb
Debian GNU/Linux 3.1 (sarge)
http://security.debian.org/pool/updates/main/s/sql-ledger/sql-ledger_2 .4.7-2sarge1_all.deb
References
SQL-Ledger Session ID Authentication Bypass Vulnerability
References:
References:
- SQL-Ledger Web Site (SQL-Ledger)