5
CVSSv2

CVE-2008-2045

Published: 01/05/2008 Updated: 11/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote malicious users to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sugarcrm sugarcrm 4.5.1

sugarcrm sugarcrm 5.0.0

Exploits

Name SugarCRM – Local File Disclosure SugarCRM wwwsugarcrmcom/docs/Release_Notes/OpenSource_ReleaseNotes_451j/ Advisories Sugar_Release_Notes_451j26html (Bug 20522) dlsugarforgeorg/sugarcrm/SugarCE50Latest/SugarCE500/ ...