Description
login.pl in SQL-Ledger before 2.6.21 and LedgerSMB before 1.1.5 allows remote attackers to execute arbitrary Perl code via the "-e" flag in the script parameter, which is used as an argument to the perl program.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1239-1 | New sql-ledger packages fix arbitrary code execution |
EUVD |
EUVD-2006-5856 | login.pl in SQL-Ledger before 2.6.21 and LedgerSMB before 1.1.5 allows remote attackers to execute arbitrary Perl code via the "-e" flag in the script parameter, which is used as an argument to the perl program. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T20:04:55.662Z
Reserved: 2006-11-14T00:00:00.000Z
Link: CVE-2006-5872
No data.
Status : Modified
Published: 2006-12-18T00:28:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2006-5872
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD