Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot) sequences in the (1) module, (2) action, or (3) theme parameters to index.php, (4) the theme parameter to Login.php, and possibly other parameters or scripts.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2004-12-15T05:00:00
Updated: 2024-08-08T00:46:12.380Z
Reserved: 2004-12-14T00:00:00
Link: CVE-2004-1227
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-01-10T05:00:00.000
Modified: 2024-11-20T23:50:24.677
Link: CVE-2004-1227
Redhat
No data.