CVE-2009-4046 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in FrontAccounting (FA) 2.2.x before 2.2 RC allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) bank_accounts.php (2) currencies.php (3) exchange_rates.php (4) gl_account_types.php and (5) gl_accounts.php in gl/manage/; and (6) audit_trail_db.inc (7) comments_db.inc (8) inventory_db.inc (9) manufacturing_db.inc and (10) references_db.inc in includes/db/.
Reference
http://frontaccounting.net/wb3/pages/posts/release-2.2-rc104.php http://sourceforge.net/projects/frontaccounting/files/FrontAccounting-2/2.220RC/frontaccount-2.2RC.tar.gz/download http://www.vupen.com/english/advisories/2009/3223
Share on: