The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbitrary password to the admin interface.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/508559/100/0/threaded | mailing list |
http://secunia.com/advisories/37877 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/37431 | vdb entry |