Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:26922
HistoryAug 27, 2011 - 12:00 a.m.

SQL-Ledger patch update for SQL injection

2011-08-2700:00:00
vulners.com
46

Hi all;

We have been informed that SQL-Ledger 2.8.34 has in fact been released
patching the security hole previously reported in LedgerSMB 1.2.24 and
Lower. This is an SQL injection issue.

I haven't been been able to find a CVE listing for this yet. Secunia
has assigned this the id of SA45649 for LedgerSMB. I expect to send a
full disclosure email discussing the vulnerability in a week.

Best Wishes,
Chris Travers