SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the...
Vulnerability Description
SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4244
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.sql-ledger.org/cgi-bin/nav.pl?page=news.html&title=What%27s%20New
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28671
- http://www.securityfocus.com/bid/19758
- http://secunia.com/advisories/21689
- http://www.securityfocus.com/archive/1/444741/100/0/threaded
- http://www.securityfocus.com/archive/1/445512
- http://securityreason.com/securityalert/1472
More from sql-ledger
View All →Affected Vendor
sql-ledger
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.