Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
LedgerSMB 1.0.0 and SQL-Ledger 2.6.18 and earler arbitrary code execution Sep 12 2006 03:00AM
Chris Travers (chris metatrontech com)
Hi all;

Summary:
A directory transversal issue was found in LedgerSMB 1.0.0 involving the
terminal variable. This vulnerability was inherited from the SQL-Ledger
codebase. Due to the fact that SQL-Ledger has a built-in text editor,
this issue could result in arbitrary code execution on the ser...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus