Another security issue has been found in LedgerSMB versions 1.1.5 and below and all versions of SQL-Ledger which allows an attacker to engage in directory transversal, retrieval of sensitive information, user account fabrication, or even arbitrary code execution.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54816/ledger-multi.txt
Source: https://packetstormsecurity.com/files/54816/ledger-multi.txt.html

