Lucene search

K
cveMitreCVE-2005-4087
HistoryDec 08, 2005 - 11:03 a.m.

CVE-2005-4087

2005-12-0811:03:00
mitre
web.nvd.nist.gov
33
php
remote file include vulnerability
sugarcrm
security
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

High

EPSS

0.01

Percentile

83.3%

PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to execute arbitrary PHP code via a URL in the beanFiles array parameter.

Affected configurations

Nvd
Node
sugarcrmsugar_suiteMatch3.5
OR
sugarcrmsugar_suiteMatch4.0_beta
VendorProductVersionCPE
sugarcrmsugar_suite3.5cpe:2.3:a:sugarcrm:sugar_suite:3.5:*:*:*:*:*:*:*
sugarcrmsugar_suite4.0_betacpe:2.3:a:sugarcrm:sugar_suite:4.0_beta:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

High

EPSS

0.01

Percentile

83.3%

Related for CVE-2005-4087