PT-2008-5381 · Sql Ledger+2 · Sql-Ledger+2

Seneca Cunningham

·

Publicado

2008-09-15

·

Atualizado

2024-02-09

·

CVE-2008-4078

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LedgerSMB versions prior to 1.2.15 SQL-Ledger versions prior to 2.8.18
Description The issue allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. This is a SQL injection vulnerability in the AR/AP transaction report.
Recommendations For LedgerSMB versions prior to 1.2.15, update to version 1.2.15 or later. For SQL-Ledger versions prior to 2.8.18, update to version 2.8.18 or later.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4078

Produtos afetados

Debian
Ledgersmb
Sql-Ledger