Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error function that returns from execution.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ledgersmb | Ledgersmb | 1.0.0 (including) | 1.0.0 (including) |
Ledgersmb | Ledgersmb | 1.1.0 (including) | 1.1.0 (including) |
Ledgersmb | Ledgersmb | 1.1.1 (including) | 1.1.1 (including) |
Sql-ledger | Sql-ledger | * | 2.6.24 (including) |
Sql-ledger | Ubuntu | dapper | * |
Sql-ledger | Ubuntu | edgy | * |
Sql-ledger | Ubuntu | feisty | * |
Sql-ledger | Ubuntu | gutsy | * |
Sql-ledger | Ubuntu | upstream | * |