CVE
- Id
- 25280
- CVE No.
- CVE-2007-1923
- Status
- Candidate
- Description
- (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests.
- Phase
- Assigned (20070410)
- Votes
- None (candidate not yet proposed)
- Comments