LedgerSMB Login.PL Authentication Bypass Vulnerability
BID:24940
Info
LedgerSMB Login.PL Authentication Bypass Vulnerability
| Bugtraq ID: | 24940 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-3907 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2007 12:00AM |
| Updated: | May 07 2015 05:36PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
LedgerSMB LedgerSMB 1.2.6 LedgerSMB LedgerSMB 1.2.5 LedgerSMB LedgerSMB 1.2.4 LedgerSMB LedgerSMB 1.2.3 LedgerSMB LedgerSMB 1.2.2 LedgerSMB LedgerSMB 1.2.1 LedgerSMB LedgerSMB 1.2 |
| Not Vulnerable: |
LedgerSMB LedgerSMB 1.2.7 |
Discussion
LedgerSMB Login.PL Authentication Bypass Vulnerability
LedgerSMB is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the application.
This issue affects LedgerSMB 1.2.6 and prior versions.
LedgerSMB is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the application.
This issue affects LedgerSMB 1.2.6 and prior versions.
Exploit / POC
LedgerSMB Login.PL Authentication Bypass Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
LedgerSMB Login.PL Authentication Bypass Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
LedgerSMB Login.PL Authentication Bypass Vulnerability
References:
References: