SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-09-15 08:14
Updated : 2018-10-11 13:50
NVD link : CVE-2008-4078
Mitre link : CVE-2008-4078
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
dws_systems_inc.
- sql-ledger
sql-ledger
- sql-ledger
ledgersmb
- ledgersmb