CVE-2007-1923

(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests.
Configurations

Configuration 1

cpe:2.3:a:ledgersmb:ledgersmb:*:*:*:*:*:*:*:*
cpe:2.3:a:dws_systems_inc.:sql-ledger:*:*:*:*:*:*:*:*

Information

Published : 2007-04-10 11:19

Updated : 2018-10-16 04:41


NVD link : CVE-2007-1923

Mitre link : CVE-2007-1923

Products Affected
No products.