CVE Vulnerabilities

CVE-2005-4086

Published: Dec 08, 2005 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to include arbitrary local files via .. sequences in the beanFiles array parameter.

Affected Software

Name Vendor Start Version End Version
Sugar_suite Sugarcrm 3.5 (including) 3.5 (including)
Sugar_suite Sugarcrm 4.0_beta (including) 4.0_beta (including)

References