LedgerSMB Unspecified SQL Injection Vulnerabilities
BID:20749
Info
LedgerSMB Unspecified SQL Injection Vulnerabilities
| Bugtraq ID: | 20749 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5589 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2006 12:00AM |
| Updated: | Apr 06 2007 03:22AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
LedgerSMB LedgerSMB 1.1 |
| Not Vulnerable: |
LedgerSMB LedgerSMB 1.2 |
Discussion
LedgerSMB Unspecified SQL Injection Vulnerabilities
LedgerSMB is prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, gain administrative access to the application, or exploit vulnerabilities in the underlying database implementation.
LedgerSMB 1.1.0 is vulnerable to these issues; other versions may be vulnerable as well.
LedgerSMB is prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.
A successful attack could allow an attacker to compromise the application, access or modify data, gain administrative access to the application, or exploit vulnerabilities in the underlying database implementation.
LedgerSMB 1.1.0 is vulnerable to these issues; other versions may be vulnerable as well.
Exploit / POC
LedgerSMB Unspecified SQL Injection Vulnerabilities
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
LedgerSMB Unspecified SQL Injection Vulnerabilities
Solution:
The vendor has released version 1.2.0 to address these issues. Please see the references for more information.
LedgerSMB LedgerSMB 1.1
Solution:
The vendor has released version 1.2.0 to address these issues. Please see the references for more information.
LedgerSMB LedgerSMB 1.1
-
LedgerSMB ledgersmb-1.2.0.tar.gz
http://downloads.sourceforge.net/ledger-smb/ledgersmb-1.2.0.tar.gz?mod time=1175710636&big_mirror=0
References
LedgerSMB Unspecified SQL Injection Vulnerabilities
References:
References:
- LedgerSMB Homepage (LedgerSMB)
- Version 1.2.0 Release Notes (LedgerSMB)
- LedgerSMB 1.2.0 finally released, fixes CVE-2006-5589 (Chris Travers)