PT-2008-5381 · Sql Ledger+2 · Sql-Ledger+2

Seneca Cunningham

·

Published

2008-09-15

·

Updated

2024-02-09

·

CVE-2008-4078

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LedgerSMB versions prior to 1.2.15 SQL-Ledger versions prior to 2.8.18
Description The issue allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. This is a SQL injection vulnerability in the AR/AP transaction report.
Recommendations For LedgerSMB versions prior to 1.2.15, update to version 1.2.15 or later. For SQL-Ledger versions prior to 2.8.18, update to version 2.8.18 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2008-4078

Affected Products

Debian
Ledgersmb
Sql-Ledger