Multiple SQL injection vulnerabilities in LedgerSMB (LSMB) 1.1.0 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (1) OE.pm, (2) AM.pm, and (3) Form.pm.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ledgersmb | Ledgersmb | * | 1.1.0 (including) |
Ledgersmb | Ledgersmb | 1.0.0 (including) | 1.0.0 (including) |