Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-4244
Description:SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.
Test IDs: 1.3.6.1.4.1.25623.1.0.57738   1.3.6.1.4.1.25623.1.0.57729  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-4244
BugTraq ID: 19758
http://www.securityfocus.com/bid/19758
Bugtraq: 20060830 SQL-Ledger serious security vulnerability and workaround (Google Search)
http://www.securityfocus.com/archive/1/444741/100/0/threaded
Bugtraq: 20060907 Full Disclosure for SQL-Ledger vulnerability CVE-2006-4244 (Google Search)
http://www.securityfocus.com/archive/1/445512
http://secunia.com/advisories/21689
http://securityreason.com/securityalert/1472
XForce ISS Database: sql-ledger-session-unauth-access(28671)
https://exchange.xforce.ibmcloud.com/vulnerabilities/28671




© 1998-2025 E-Soft Inc. All rights reserved.