CVE-2009-4045

FrontAccounting <2.1.7 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to various .inc and .php files in (1) reporting/, (2) sales/, (3) sales/includes/, (4) sales/includes/db/, (5) sales/inquiry/, (6) sales/manage/, (7) sales/view/, (8) taxes/, and (9) taxes/db/.

References (4)

Core 4

Scores

EPSS 0.0106
EPSS Percentile 61.1%

Details

CWE
CWE-89
Status published
Products (16)
frontaccounting/frontaccounting 2.0
frontaccounting/frontaccounting 2.0.1
frontaccounting/frontaccounting 2.0.2
frontaccounting/frontaccounting 2.0.3
frontaccounting/frontaccounting 2.0.4
frontaccounting/frontaccounting 2.0.5
frontaccounting/frontaccounting 2.0.6
frontaccounting/frontaccounting 2.0.7
frontaccounting/frontaccounting 2.1
frontaccounting/frontaccounting 2.1.0 beta (3 CPE variants)
... and 6 more
Published Nov 20, 2009
Tracked Since Feb 18, 2026