CVE-2007-1923

(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ledgersmb:ledgersmb:*:*:*:*:*:*:*:*
cpe:2.3:a:sql-ledger:sql-ledger:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-04-10 23:19

Updated : 2024-02-02 18:26


NVD link : CVE-2007-1923

Mitre link : CVE-2007-1923

CVE.ORG link : CVE-2007-1923


JSON object : View

Products Affected

sql-ledger

  • sql-ledger

ledgersmb

  • ledgersmb