slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Saleslogix | Best_software | * | * |
Saleslogix | Saleslogix_corporation | 2000.0 (including) | 2000.0 (including) |