CVE Vulnerabilities

CVE-2005-4086

Published: Dec 08, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to include arbitrary local files via .. sequences in the beanFiles array parameter.

Affected Software

NameVendorStart VersionEnd Version
Sugar_suiteSugarcrm3.5 (including)3.5 (including)
Sugar_suiteSugarcrm4.0_beta (including)4.0_beta (including)

References