CVE

Id
41472  
CVE No.
CVE-2009-4037  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7, and 2.2.x before 2.2 RC, allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/db/users_db.inc, and various other .inc and .php files under (2) admin/, (3) dimensions/, (4) gl/, (5) inventory/, (6) manufacturing/, and (7) purchasing/.  
Phase
Assigned (20091120)  
Votes
None (candidate not yet proposed)  
Comments