OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[SA31843] LedgerSMB Denial of Service and SQL Injection Vulnerabilities

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Thu Sep 11 2008 - 10:24:05 CDT


----------------------------------------------------------------------

We have updated our website, enjoy!
http://secunia.com/

----------------------------------------------------------------------

TITLE:
LedgerSMB Denial of Service and SQL Injection Vulnerabilities

SECUNIA ADVISORY ID:
SA31843

VERIFY ADVISORY:
http://secunia.com/advisories/31843/

CRITICAL:
Less critical

IMPACT:
Manipulation of data, DoS

WHERE:
From remote

SOFTWARE:
LedgerSMB 1.x
http://secunia.com/advisories/product/11926/

DESCRIPTION:
Some vulnerabilities have been reported in LedgerSMB, which can be
exploited by malicious users to conduct SQL injection attacks and
malicious people to cause a DoS (Denial of Service).

1) Certain CGI scripts accept POST requests up to the length
specified in the "Content-Length" header. This can be exploited to
e.g. cause a DoS by exhausting the system resources via large POST
request.

2) Input passed to an unspecified parameter in the AR/AP Transactions
Report is not properly sanitised before being used in SQL queries.
This can be exploited by malicious users to manipulate SQL queries by
injecting arbitrary SQL code.

Successful exploitation of this vulnerability requires valid user
credentials.

SOLUTION:
Update to version 1.2.16.

PROVIDED AND/OR DISCOVERED BY:
1) Chris Murtagh
2) Seneca Cunningham

ORIGINAL ADVISORY:
http://www.ledgersmb.org/node/70
http://sourceforge.net/mailarchive/message.php?msg_name=f5cca7ed0809091802n72ad98d3p1e3edc0d19cd7a6b%40mail.gmail.com

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/advisories/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------