The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbitrary password to the admin interface.
http://www.securityfocus.com/bid/37431
http://www.securityfocus.com/archive/1/508559/100/0/threaded