The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


LedgerSMB < 1.2.8, SQL-Ledger 2.x Multiple SQL Injection Issues


<< Previous INDEX Search src / Print Next >>
Date: Tue, 9 Oct 2007 09:31:14 -0700
From: "Chris Travers" <chris.travers@gmail.com.>
To: [email protected]
Subject: LedgerSMB < 1.2.8, SQL-Ledger 2.x Multiple SQL Injection Issues
In-Reply-To: <f5cca7ed0710090930g5df9e383vd7f092ccae55c700@mail.gmail.com.>
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
References: <f5cca7ed0710090930g5df9e383vd7f092ccae55c700@mail.gmail.com.>
X-Virus-Scanned: antivirus-gw at tyumen.ru

Severity:  Critical
Effect:  Compromise of FInancial Data, deletion of audit trails,
alteration of system settings, disclosure of confidential information
possible in some setups.
Affected products:  LedgerSMB 1.0.0-1.2.7 , SQL-Ledger 2.x (all versions).

1:  SQL injection issue in invoice quantity field
2:  SQL injection issue in sort field.

Solution to issue on LedgerSMB:  Upgrade to 1.2.8.

Solution to issue on SQL-Ledger:  Unfortunately the maintainer of
SQL-Ledger has declined to fix any of the SQL injection issues we have
sent his way.  Even correcting these, there are many SQL injection
issues in that application.  Our official recommendation for
SQL-Ledger users is to restrict access to database relations to the
least privelege necessary.  While this does not entirely solve the
issues, it does limit the damage considerably.

Best Wishes,
Chris Travers


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру