CVE Vulnerabilities

CVE-2004-1610

Published: Oct 18, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.

Affected Software

NameVendorStart VersionEnd Version
SaleslogixBest_software**
SaleslogixSaleslogix_corporation2000.0 (including)2000.0 (including)

References