SQL-Ledger Multiple Remote Vulnerabilities
BID:37431
Info
SQL-Ledger Multiple Remote Vulnerabilities
| Bugtraq ID: | 37431 |
| Class: | Unknown |
| CVE: |
CVE-2009-3581 CVE-2009-3582 CVE-2009-3583 CVE-2009-3584 CVE-2009-4402 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 21 2009 12:00AM |
| Updated: | Jan 25 2010 06:41PM |
| Credit: | Alexander Klink |
| Vulnerable: |
SQL-Ledger SQL-Ledger 2.8.24 SQL-Ledger SQL-Ledger 2.6.26 SQL-Ledger SQL-Ledger 2.6.25 SQL-Ledger SQL-Ledger 2.6.21 SQL-Ledger SQL-Ledger 2.6.19 SQL-Ledger SQL-Ledger 2.6.18 SQL-Ledger SQL-Ledger 2.6.17 SQL-Ledger SQL-Ledger 2.4.7 LedgerSMB LedgerSMB 1.2.15 LedgerSMB LedgerSMB 1.2.8 LedgerSMB LedgerSMB 1.2.7 LedgerSMB LedgerSMB 1.2.6 LedgerSMB LedgerSMB 1.2.5 LedgerSMB LedgerSMB 1.2.4 LedgerSMB LedgerSMB 1.2.3 LedgerSMB LedgerSMB 1.2.2 LedgerSMB LedgerSMB 1.2.1 LedgerSMB LedgerSMB 1.2 LedgerSMB LedgerSMB 1.1.9 LedgerSMB LedgerSMB 1.1.8 LedgerSMB LedgerSMB 1.1.5 LedgerSMB LedgerSMB 1.1 LedgerSMB LedgerSMB 1.1 LedgerSMB LedgerSMB 1.0 p1 LedgerSMB LedgerSMB 1.0 LedgerSMB LedgerSMB 1.12.15 |
| Not Vulnerable: | |
Discussion
SQL-Ledger Multiple Remote Vulnerabilities
SQL-Ledger is prone to multiple HTML-injection issues, a SQL-injection issue, a local file-include issue, an insecure-session-cookie issue, and an administrator-password weakness.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, obtain sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database.
SQL-Ledger 2.8.84 is vulnerable; other versions may also be affected.
SQL-Ledger is prone to multiple HTML-injection issues, a SQL-injection issue, a local file-include issue, an insecure-session-cookie issue, and an administrator-password weakness.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, obtain sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database.
SQL-Ledger 2.8.84 is vulnerable; other versions may also be affected.
Exploit / POC
SQL-Ledger Multiple Remote Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
SQL-Ledger Multiple Remote Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
SQL-Ledger Multiple Remote Vulnerabilities
References:
References:
- LedgerSMB Homepage (LedgerSMB)
- SQL-Ledger �?? several vulnerabilities (Alexander Klink (alexander.klinksit.fraunhofer.de))
- SQL-Ledger Homepage (SQL-Ledger)
- CVE-2009-3583, confirming problem and adding info (Chris Travers
) - FWD: LedgerSMB Security Advisory: Multiple Vulnerabilities (Chris Travers
)