(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0.
References
Link | Resource |
---|---|
http://osvdb.org/38217 | Broken Link |
http://osvdb.org/38218 | Broken Link |
http://securityreason.com/securityalert/2552 | Third Party Advisory |
http://www.securityfocus.com/archive/1/464880/100/0/threaded | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/23352 | Broken Link Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33494 | Third Party Advisory VDB Entry |
https://github.com/ledgersmb/LedgerSMB/blob/master/Changelog | Release Notes |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2007-04-10T00:00:00
Updated: 2023-09-25T04:58:55.612724
Reserved: 2007-04-10T00:00:00
Link: CVE-2007-1923
JSON object: View
NVD Information
Status : Analyzed
Published: 2007-04-10T23:19:00.000
Modified: 2024-02-02T18:26:00.153
Link: CVE-2007-1923
JSON object: View
Redhat Information
No data.
CWE