3.5
CVSSv2

CVE-2009-3581

Published: 23/12/2009 Updated: 21/11/2024

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or HTML via (1) the DCN Description field in the Accounts Receivables menu item for Add Transaction, (2) the Description field in the Accounts Payable menu item for Add Transaction, or the name field in (3) the Customers menu item for Add Customer or (4) the Vendor menu item for Add Vendor.

Vulnerable Product Search on Vulmon Subscribe to Product

sql-ledger sql-ledger 2.8.24

Vendor Advisories

Debian Bug report logs - #562639 CVE-2009-4402 CVE-2009-3580 CVE-2009-3581 CVE-2009-3582 CVE-2009-3583 CVE-2009-3584 Package: sql-ledger; Maintainer for sql-ledger is Robert James Clay <jame@rocasaus>; Source for sql-ledger is src:sql-ledger (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <iuculano@debianorg> ...

Exploits

SQL-Ledger suffers from cross site scripting, cross site request forgery, local file inclusion, SQL injection, and various other security vulnerabilities ...