Vulnerabilities > CVE-2006-2460 - Unspecified vulnerability in Sugarcrm
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description | Sugar Suite Open Source <= 4.2 (OptimisticLock) Remote Exploit. CVE-2006-2460. Webapps exploit for php platform |
file | exploits/php/webapps/1785.php |
id | EDB-ID:1785 |
last seen | 2016-01-31 |
modified | 2006-05-14 |
platform | php |
port | |
published | 2006-05-14 |
reporter | rgod |
source | https://www.exploit-db.com/download/1785/ |
title | Sugar Suite Open Source <= 4.2 OptimisticLock Remote Exploit |
type | webapps |
Nessus
NASL family | CGI abuses |
NASL id | SUGARCRM_42.NASL |
description | The version of SugarCRM installed on the remote host fails to sanitize input to various parameters and scripts before using it to include PHP code from other files. Provided PHP |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21570 |
published | 2006-05-16 |
reporter | This script is Copyright (C) 2006-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/21570 |
title | SugarCRM <= 4.2.0a Multiple Script sugarEntry Parameter Remote File Inclusion |
code |
|
References
- http://retrogod.altervista.org/sugar_suite_42_incl_xpl.html
- http://retrogod.altervista.org/sugar_suite_42_incl_xpl.html
- http://secunia.com/advisories/20072
- http://secunia.com/advisories/20072
- http://securityreason.com/securityalert/921
- http://securityreason.com/securityalert/921
- http://securitytracker.com/id?1016087
- http://securitytracker.com/id?1016087
- http://www.osvdb.org/25532
- http://www.osvdb.org/25532
- http://www.securityfocus.com/archive/1/434009/100/0/threaded
- http://www.securityfocus.com/archive/1/434009/100/0/threaded
- http://www.securityfocus.com/bid/17987
- http://www.securityfocus.com/bid/17987
- http://www.vupen.com/english/advisories/2006/1791
- http://www.vupen.com/english/advisories/2006/1791
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26451
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26451
- https://www.exploit-db.com/exploits/1785
- https://www.exploit-db.com/exploits/1785