Lucene search

K
cveMitreCVE-2005-4086
HistoryDec 08, 2005 - 11:03 a.m.

CVE-2005-4086

2005-12-0811:03:00
mitre
web.nvd.nist.gov
27
cve-2005-4086
sugar suite
customer relationship management
vulnerability
remote attack
directory traversal

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

High

EPSS

0.01

Percentile

83.4%

Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to include arbitrary local files via “…” sequences in the beanFiles array parameter.

Affected configurations

Nvd
Node
sugarcrmsugar_suiteMatch3.5
OR
sugarcrmsugar_suiteMatch4.0_beta
VendorProductVersionCPE
sugarcrmsugar_suite3.5cpe:2.3:a:sugarcrm:sugar_suite:3.5:*:*:*:*:*:*:*
sugarcrmsugar_suite4.0_betacpe:2.3:a:sugarcrm:sugar_suite:4.0_beta:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

High

EPSS

0.01

Percentile

83.4%

Related for CVE-2005-4086