CVE-2007-1923

(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dws_systems_inc.:sql-ledger:*:*:*:*:*:*:*:*
cpe:2.3:a:ledgersmb:ledgersmb:*:*:*:*:*:*:*:*

Information

Published : 2007-04-10 23:19

Updated : 2018-10-16 16:41


NVD link : CVE-2007-1923

Mitre link : CVE-2007-1923


JSON object : View

Products Affected

ledgersmb

  • ledgersmb

dws_systems_inc.

  • sql-ledger