7.5
CVSSv2

CVE-2005-4087

Published: 08/12/2005 Updated: 20/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the beanFiles array parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sugarcrm sugar suite 3.5

sugarcrm sugar suite 4.0_beta

Exploits

<?php # ---sugar_suite_40beta_xplphp # # # # Sugar Suite Open Source <= 40 beta remote code execution # # coded by rgod # # ...
/* gcc -o sugar sugarc Usage /sugar [host] [/path/] [site] [cmd] Sugar Suite Open Source <= 40 beta remote code execution (c code) coded by: pointslash v credits: rgod, unitedasia host - hostname (ex: wwwsitenamecom) path - path (ex: /sugar/ or just / ) site - remote location ( ex: wwwsomesitecom/filetxt) cmd - specify a com ...