LedgerSMB Replay Security Bypass Vulnerability
BID:65307
Info
LedgerSMB Replay Security Bypass Vulnerability
| Bugtraq ID: | 65307 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 02 2014 12:00AM |
| Updated: | Feb 02 2014 12:00AM |
| Credit: | Chris Travers |
| Vulnerable: |
LedgerSMB LedgerSMB 1.3.35 LedgerSMB LedgerSMB 1.3.0 |
| Not Vulnerable: |
LedgerSMB LedgerSMB 1.3.36 |
Discussion
LedgerSMB Replay Security Bypass Vulnerability
LedgerSMB is prone to a security-bypass vulnerability.
Successfully exploiting this issue will allow an attacker to perform replay attacks. This may lead to other attacks.
LedgerSMB 1.3.0 through 1.3.35 are vulnerable; other versions may also be affected.
LedgerSMB is prone to a security-bypass vulnerability.
Successfully exploiting this issue will allow an attacker to perform replay attacks. This may lead to other attacks.
LedgerSMB 1.3.0 through 1.3.35 are vulnerable; other versions may also be affected.
Exploit / POC
LedgerSMB Replay Security Bypass Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
LedgerSMB Replay Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
LedgerSMB Replay Security Bypass Vulnerability
References:
References:
- LedgerSMB Homepage (LedgerSMB)
- Security advisory, LedgerSMB 1.3.0-1.3.36 (Chris Travers)