Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sugarcrm sugarcrm 3.5 vulnerabilities and exploits
(subscribe to this query)
6.4
CVSSv2
CVE-2006-2460
Sugar Suite Open Source (SugarCRM) 4.2 and previous versions, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote malicious users to conduct attacks such as directory traversal or PHP remote ...
Sugarcrm Sugarcrm 3.5
Sugarcrm Sugarcrm 4.0
Sugarcrm Sugarcrm 4.1
Sugarcrm Sugarcrm 4.2
1 EDB exploit
7.5
CVSSv2
CVE-2009-2978
SQL injection vulnerability in SugarCRM 4.5.1o and previous versions, 5.0.0k and previous versions, and 5.2.0g and previous versions, allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Sugarcrm Sugarcrm 1.0
Sugarcrm Sugarcrm 1.0f
Sugarcrm Sugarcrm 1.1e
Sugarcrm Sugarcrm 1.1f
Sugarcrm Sugarcrm 3.5.1
Sugarcrm Sugarcrm 4.0
Sugarcrm Sugarcrm
Sugarcrm Sugarcrm 5.2a
Sugarcrm Sugarcrm 5.2f
Sugarcrm Sugarcrm 1.1c
Sugarcrm Sugarcrm 1.1d
Sugarcrm Sugarcrm 3.0.1
Sugarcrm Sugarcrm 3.5
Sugarcrm Sugarcrm 4.5.0f
Sugarcrm Sugarcrm 4.5.1
Sugarcrm Sugarcrm 5.2d
Sugarcrm Sugarcrm 5.2c
Sugarcrm Sugarcrm 1.0g
Sugarcrm Sugarcrm 1.1
Sugarcrm Sugarcrm 1.5d
Sugarcrm Sugarcrm 2.0.1
Sugarcrm Sugarcrm 4.0.1
7.5
CVSSv2
CVE-2006-5082
Unspecified vulnerability in Sugar Suite Open Source (SugarCRM) prior to 4.2.1 Patch C (20060917) has unspecified impact, related to code execution, and unspecified attack vectors.
Sugarcrm Sugar Suite 4.1
Sugarcrm Sugar Suite 4.2
Sugarcrm Sugar Suite 4.2.1
Sugarcrm Sugar Suite 4.0.1
Sugarcrm Sugar Suite 4.0 Beta
Sugarcrm Sugar Suite 3.5
Sugarcrm Sugar Suite 3.5.1
4
CVSSv2
CVE-2011-0745
SugarCRM prior to 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remote authenticated users to discover (1) the names of customers via a ShowDuplicates action to the Accounts module, reachable thro...
Sugarcrm Sugarcrm 5.5
Sugarcrm Sugarcrm 4.1
Sugarcrm Sugarcrm 1.1b
Sugarcrm Sugarcrm 1.1c
Sugarcrm Sugarcrm 2.0.1c
Sugarcrm Sugarcrm 5.2.0g
Sugarcrm Sugarcrm 4.5.1i
Sugarcrm Sugarcrm 3.5.1
Sugarcrm Sugarcrm 5.2e
Sugarcrm Sugarcrm 5.0.0
Sugarcrm Sugarcrm 5.1.0
Sugarcrm Sugarcrm 6.0.2
Sugarcrm Sugarcrm 6.0.1
Sugarcrm Sugarcrm 6.0
Sugarcrm Sugarcrm 5.2h
Sugarcrm Sugarcrm 3.5
Sugarcrm Sugarcrm 1.0
Sugarcrm Sugarcrm 1.0f
Sugarcrm Sugarcrm 1.0g
Sugarcrm Sugarcrm 1.1f
Sugarcrm Sugarcrm 1.5d
Sugarcrm Sugarcrm 5.2g
1 EDB exploit
7.5
CVSSv2
CVE-2005-4087
PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the beanFiles array parameter.
Sugarcrm Sugar Suite 3.5
Sugarcrm Sugar Suite 4.0 Beta
2 EDB exploits
5
CVSSv2
CVE-2005-4086
Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and previous versions allows remote malicious users to include arbitrary local files via ".." sequences in the beanFiles array paramete...
Sugarcrm Sugar Suite 3.5
Sugarcrm Sugar Suite 4.0 Beta
2 EDB exploits
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started