LedgerSMB/SQL-Ledger SQL Injection Vulnerability
BID:49270
Info
LedgerSMB/SQL-Ledger SQL Injection Vulnerability
| Bugtraq ID: | 49270 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2011 12:00AM |
| Updated: | Aug 31 2011 08:00PM |
| Credit: | Erik Huelsmann |
| Vulnerable: |
SQL-Ledger SQL-Ledger 2.8.33 SQL-Ledger SQL-Ledger 2.8.24 SQL-Ledger SQL-Ledger 2.6.26 SQL-Ledger SQL-Ledger 2.6.25 SQL-Ledger SQL-Ledger 2.6.21 SQL-Ledger SQL-Ledger 2.6.19 SQL-Ledger SQL-Ledger 2.6.18 SQL-Ledger SQL-Ledger 2.6.17 LedgerSMB LedgerSMB 1.2.24 LedgerSMB LedgerSMB 1.2.15 LedgerSMB LedgerSMB 1.2.8 LedgerSMB LedgerSMB 1.2.7 LedgerSMB LedgerSMB 1.2.6 LedgerSMB LedgerSMB 1.2.5 LedgerSMB LedgerSMB 1.2.4 LedgerSMB LedgerSMB 1.2.3 LedgerSMB LedgerSMB 1.2.2 LedgerSMB LedgerSMB 1.2.1 LedgerSMB LedgerSMB 1.2 |
| Not Vulnerable: |
SQL-Ledger SQL-Ledger 2.8.34 LedgerSMB LedgerSMB 1.2.25 |
Discussion
LedgerSMB/SQL-Ledger SQL Injection Vulnerability
LedgerSMB and SQL-Ledger are prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
LedgerSMB and SQL-Ledger are prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
LedgerSMB/SQL-Ledger SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
LedgerSMB/SQL-Ledger SQL Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
LedgerSMB/SQL-Ledger SQL Injection Vulnerability
References:
References:
- LedgerSMB Download Page (Sourceforge)
- LedgerSMB Homepage (LedgerSMB)
- Full disclosure for SA45649, SQL Injection in LedgerSMB and SQL-Ledger (Chris Travers
) - Security advisory: SQL Injection in LedgerSMB 1.2.24 and lower (chris.travers)