Creditee: CYBSEC-Labs Team

Known Contact Information:

  • (as of 2009-12-10)

Known Affiliations:

Disclosed Vulnerabilities (36):

Disc. DateOSVDB IDCVEIDTitle
2010-10-29 71336 Front Accounting (FA) Index.php GET HTTP Request XSS
2010-10-29 71431 Front Accounting (FA) admin/fiscalyears.php from_date Parameter SQL Injection
2010-10-29 71337 Front Accounting (FA) /admin/attachments.php Multiple Parameter XSS
2010-10-29 71338 Front Accounting (FA) /admin/change_current_user_password.php POST HTTP Request XSS
2010-10-29 71339 Front Accounting (FA) /admin/display_prefs.php Multiple Parameter XSS
2010-10-29 71340 Front Accounting (FA) /admin/fiscalyears.php Multiple Parameter XSS
2010-10-29 71341 Front Accounting (FA) /admin/forms_setup.php Multiple Parameter XSS
2010-10-29 71342 Front Accounting (FA) /admin/print_profiles.php _focus Parameter XSS
2010-10-29 71343 Front Accounting (FA) /admin/printers.php Multiple Parameter XSS
2010-10-29 71344 Front Accounting (FA) /admin/view_print_transaction.php Multiple Parameter XSS
2010-10-29 71345 Front Accounting (FA) /admin/void_transaction.php Multiple Parameter XSS
2010-10-29 71346 Front Accounting (FA) /dimensions/dimension_entry.php Multiple Parameter XSS
2010-10-29 71347 Front Accounting (FA) /dimensions/inquiry/search_dimensions.php Multiple Parameter XSS
2010-10-29 71348 Front Accounting (FA) /dimensions/view/view_dimension.php trans_no Parameter XSS
2010-10-29 71349 Front Accounting (FA) /gl/bank_account_reconcile.php Multiple Parameter XSS
2010-10-29 71350 Front Accounting (FA) /gl/bank_transfer.php Multiple Parameter XSS
2010-10-29 71351 Front Accounting (FA) /sales/manage/recurrent_invoices.php Multiple Parameter XSS
2010-10-29 71432 Front Accounting (FA) dimensions/dimension_entry.php Multiple Parameter SQL Injection
2010-10-29 71433 Front Accounting (FA) dimensions/view/view_dimension.php trans_no Parameter SQL Injection
2010-10-29 71434 Front Accounting (FA) gl/bank_account_reconcile.php reconcile_date Parameter SQL Injection
2010-10-29 71435 Front Accounting (FA) gl/inquiry/balance_sheet.php TransToDate Parameter SQL Injection
2010-10-29 71436 Front Accounting (FA) gl/inquiry/bank_inquiry.php TransToDate Parameter SQL Injection
2010-10-29 71437 Front Accounting (FA) gl/inquiry/gl_account_inquiry.php TransToDate Parameter SQL Injection
2010-10-29 71438 Front Accounting (FA) gl/inquiry/gl_trial_balance.php TransToDate Parameter SQL Injection
2010-10-29 71439 Front Accounting (FA) gl/inquiry/profit_loss.php TransToDate Parameter SQL Injection
2010-10-29 71440 Front Accounting (FA) gl/inquiry/tax_inquiry.php TransToDate Parameter SQL Injection
2010-10-29 71441 Front Accounting (FA) gl/inquiry/journal_inquiry.php Multiple Parameter SQL Injection
2010-10-29 71442 Front Accounting (FA) inventory/inquiry/stock_movements.php Multiple Parameter SQL Injection
2010-10-29 71443 Front Accounting (FA) manufacturing/work_order_add_finished.php Multiple Parameter SQL Injection
2010-10-29 71444 Front Accounting (FA) manufacturing/work_order_issue.php Multiple Parameter SQL Injection
2010-10-29 71445 Front Accounting (FA) purchasing/po_receive_items.php PONumber Parameter SQL Injection
2010-10-29 71446 Front Accounting (FA) purchasing/supplier_credit.php Multiple Parameter SQL Injection
2010-10-29 71447 Front Accounting (FA) reporting/prn_redirect.php PARAM_1 Parameter SQL Injection
2010-10-29 71448 Front Accounting (FA) sales/customer_credit_invoice.php InvoiceNumber Parameter SQL Injection
2010-10-29 71471 Front Accounting (FA) /purchasing/allocations/supplier_allocate.php trans_no Parameter XSS
2009-12-10 60908 2009-4603 SAP Multiple Products sapstartsrv.exe Crafted Request Remote DoS

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use