LedgerSMB/SQL-Ledger Multiple SQL Injection Vulnerabilities
BID:25979
Info
LedgerSMB/SQL-Ledger Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 25979 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5372 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | Chris Travers is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
SQL-Ledger SQL-Ledger 2.6.26 SQL-Ledger SQL-Ledger 2.6.25 SQL-Ledger SQL-Ledger 2.6.21 SQL-Ledger SQL-Ledger 2.6.19 SQL-Ledger SQL-Ledger 2.6.18 SQL-Ledger SQL-Ledger 2.6.17 SQL-Ledger SQL-Ledger 2.4.7 LedgerSMB LedgerSMB 1.2.7 LedgerSMB LedgerSMB 1.2.6 LedgerSMB LedgerSMB 1.2.5 LedgerSMB LedgerSMB 1.2.4 LedgerSMB LedgerSMB 1.2.3 LedgerSMB LedgerSMB 1.2.2 LedgerSMB LedgerSMB 1.2.1 LedgerSMB LedgerSMB 1.2 LedgerSMB LedgerSMB 1.1.9 LedgerSMB LedgerSMB 1.1.8 LedgerSMB LedgerSMB 1.1.5 LedgerSMB LedgerSMB 1.1 LedgerSMB LedgerSMB 1.0 p1 LedgerSMB LedgerSMB 1.0 |
| Not Vulnerable: |
LedgerSMB LedgerSMB 1.2.8 |
Discussion
LedgerSMB/SQL-Ledger Multiple SQL Injection Vulnerabilities
LedgerSMB and SQL-Ledger are prone to multiple SQL-injection vulnerabilities because they fail to properly sanitize user-supplied data before using it in an SQL query.
A remote attacker can exploit these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect LedgerSMB 1.0.0-1.2.7 and all versions of SQL-Ledger 2.x; other versions may also be affected.
LedgerSMB and SQL-Ledger are prone to multiple SQL-injection vulnerabilities because they fail to properly sanitize user-supplied data before using it in an SQL query.
A remote attacker can exploit these issues to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect LedgerSMB 1.0.0-1.2.7 and all versions of SQL-Ledger 2.x; other versions may also be affected.
Exploit / POC
LedgerSMB/SQL-Ledger Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
LedgerSMB/SQL-Ledger Multiple SQL Injection Vulnerabilities
Solution:
Please see the vendor advisories for information on obtaining updates.
Solution:
Please see the vendor advisories for information on obtaining updates.
References
LedgerSMB/SQL-Ledger Multiple SQL Injection Vulnerabilities
References:
References:
- LedgerSMB Website (LedgerSMB)
- SQL-Ledger Homepage (SQL-Ledger)
- LedgerSMB < 1.2.8, SQL-Ledger 2.x Multiple SQL Injection Issues (Chris Travers)