7.5
CVSSv2

CVE-2006-4244

Published: 31/08/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL-Ledger 2.4.4 up to and including 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote malicious users to gain access as any logged-in user by setting the cookie and the parameter to the same value.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

sql-ledger sql-ledger 2.4.14

sql-ledger sql-ledger 2.4.15

sql-ledger sql-ledger 2.4.9

sql-ledger sql-ledger 2.6.0

sql-ledger sql-ledger 2.6.1

sql-ledger sql-ledger 2.6.16

sql-ledger sql-ledger 2.6.2

sql-ledger sql-ledger 2.6.9

sql-ledger sql-ledger 2.4.16

sql-ledger sql-ledger 2.4.4

sql-ledger sql-ledger 2.6.10

sql-ledger sql-ledger 2.6.11

sql-ledger sql-ledger 2.6.3

sql-ledger sql-ledger 2.6.4

sql-ledger sql-ledger 2.4.12

sql-ledger sql-ledger 2.4.13

sql-ledger sql-ledger 2.4.7

sql-ledger sql-ledger 2.4.8

sql-ledger sql-ledger 2.6.14

sql-ledger sql-ledger 2.6.15

sql-ledger sql-ledger 2.6.7

sql-ledger sql-ledger 2.6.8

sql-ledger sql-ledger 2.6.17

sql-ledger sql-ledger 2.4.10

sql-ledger sql-ledger 2.4.11

sql-ledger sql-ledger 2.4.5

sql-ledger sql-ledger 2.4.6

sql-ledger sql-ledger 2.6.12

sql-ledger sql-ledger 2.6.13

sql-ledger sql-ledger 2.6.5

sql-ledger sql-ledger 2.6.6

Vendor Advisories

Debian Bug report logs - #386519 sql-ledger: Security vulnerability CVE-2006-4244 Package: sql-ledger; Maintainer for sql-ledger is Robert James Clay <jame@rocasaus>; Source for sql-ledger is src:sql-ledger (PTS, buildd, popcon) Reported by: Chris Morris <cimorris@durhamacuk> Date: Fri, 8 Sep 2006 08:33:01 UTC ...
Several remote vulnerabilities have been discovered in SQL Ledger, a web based double-entry accounting program, which may lead to the execution of arbitrary code The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-4244 Chris Travers discovered that the session management can be tricked into hijacki ...

Mailing Lists

LedgerSMB version 100 and SQL-Ledger versions 2618 and below suffer from a directory traversal flaw that may allow for arbitrary code execution ...
SQL-Ledger uses a fundamentally flawed approach to session authentication All versions of SQL-Ledger from 244 to the present (2617 as of this writing) are vulnerable ...