Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Security bypass vulnerability in LedgerSMB and SQL-Ledger (fixes released today) Mar 09 2007 07:26AM
Chris Travers (chris metatrontech com)
Hi all;

George Theall of Tenable Security notified the LedgerSMB core team today
of an authentication bypass vulnerability allowing full access to the
administrator interface of LedgerSMB 1.1 and SQL-Ledger 2.x. The
problem is caused by the password checking routine failing to enforce a
passwo...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus