CVE-2006-5872 Information

Description

login.pl in SQL-Ledger before 2.6.21 and LedgerSMB before 1.1.5 allows remote attackers to execute arbitrary Perl code via the -e\ flag in the script parameter which is used as an argument to the perl program.

Reference

http://secunia.com/advisories/23375 http://secunia.com/advisories/23419 http://securitytracker.com/id?1017391 http://www.debian.org/security/2006/dsa-1239 http://www.securityfocus.com/archive/1/458300/100/0/threaded http://www.securityfocus.com/bid/21634 http://www.vupen.com/english/advisories/2006/5043 http://www.vupen.com/english/advisories/2007/0407

Share on: