CVE-2007-1923
(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests.
Date published : 2007-04-10
http://www.securityfocus.com/bid/23352
http://www.securityfocus.com/archive/1/464880/100/0/threaded
