FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-5872

This CVE name corresponds to:

Entered Topic
2006-12-18 sql-ledger -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-5872
Phase Assigned(20061114)

Description

login.pl in SQL-Ledger before 2.6.21 and LedgerSMB before 1.1.5 allows remote attackers to execute arbitrary Perl code via the "-e" flag in the script parameter, which is used as an argument to the perl program.

References

Source Reference
BUGTRAQ 20070127 Full Disclosure: Arbitrary Code Execution in LedgerSMB CVE-2006-5872
DEBIAN DSA-1239
BID 21634
VUPEN ADV-2006-5043
VUPEN ADV-2007-0407
SECTRACK 1017391
SECUNIA 23375
SECUNIA 23419