Lucene search

K
cveMitreCVE-2004-1610
HistoryFeb 20, 2005 - 5:00 a.m.

CVE-2004-1610

2005-02-2005:00:00
mitre
web.nvd.nist.gov
24
saleslogix
6.1
remote execution
authenticated users
security vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.008

Percentile

82.0%

SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.

Affected configurations

Nvd
Node
best_softwaresaleslogix
OR
saleslogix_corporationsaleslogixMatch2000.0
VendorProductVersionCPE
best_softwaresaleslogix*cpe:2.3:a:best_software:saleslogix:*:*:*:*:*:*:*:*
saleslogix_corporationsaleslogix2000.0cpe:2.3:a:saleslogix_corporation:saleslogix:2000.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.008

Percentile

82.0%

Related for CVE-2004-1610