LedgerSMB < 1.2.8, SQL-Ledger 2.x Multiple SQL Injection Issues

2007.10.11
Credit: Chris Travers
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-89


CVSS Base Score: 10/10
Impact Subscore: 10/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Complete
Integrity impact: Complete
Availability impact: Complete

Severity: Critical Effect: Compromise of FInancial Data, deletion of audit trails, alteration of system settings, disclosure of confidential information possible in some setups. Affected products: LedgerSMB 1.0.0-1.2.7 , SQL-Ledger 2.x (all versions). 1: SQL injection issue in invoice quantity field 2: SQL injection issue in sort field. Solution to issue on LedgerSMB: Upgrade to 1.2.8. Solution to issue on SQL-Ledger: Unfortunately the maintainer of SQL-Ledger has declined to fix any of the SQL injection issues we have sent his way. Even correcting these, there are many SQL injection issues in that application. Our official recommendation for SQL-Ledger users is to restrict access to database relations to the least privelege necessary. While this does not entirely solve the issues, it does limit the damage considerably. Best Wishes, Chris Travers


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2017, cxsecurity.com

 

Back to Top