5
CVSSv2

CVE-2005-4086

Published: 08/12/2005 Updated: 08/03/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and previous versions allows remote malicious users to include arbitrary local files via ".." sequences in the beanFiles array parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sugarcrm sugar suite 3.5

sugarcrm sugar suite 4.0_beta

Exploits

<?php # ---sugar_suite_40beta_xplphp # # # # Sugar Suite Open Source <= 40 beta remote code execution # # coded by rgod # # ...
/* gcc -o sugar sugarc Usage /sugar [host] [/path/] [site] [cmd] Sugar Suite Open Source <= 40 beta remote code execution (c code) coded by: pointslash v credits: rgod, unitedasia host - hostname (ex: wwwsitenamecom) path - path (ex: /sugar/ or just / ) site - remote location ( ex: wwwsomesitecom/filetxt) cmd - specify a com ...