Vulnerabilities > Saleslogix Corporation

DATE CVE VULNERABILITY TITLE RISK
2004-10-18 CVE-2004-1612 Remote vulnerability in Saleslogix Corporation Saleslogix 2000.0
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a ..
network
low complexity
saleslogix-corporation
5.0
2004-10-18 CVE-2004-1611 Remote vulnerability in Best Software SalesLogix
SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port 1707.
network
high complexity
best-software saleslogix-corporation
5.1
2004-10-18 CVE-2004-1610 Remote Security vulnerability in SalesLogix
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.
network
low complexity
best-software saleslogix-corporation
7.5
2004-10-18 CVE-2004-1609 Remote vulnerability in Best Software SalesLogix
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
network
low complexity
best-software saleslogix-corporation
5.0
2004-10-18 CVE-2004-1608 Remote vulnerability in Best Software SalesLogix
SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.
network
low complexity
best-software saleslogix-corporation
7.5
2004-10-18 CVE-2004-1607 Remote vulnerability in Best Software SalesLogix
slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.
network
low complexity
best-software saleslogix-corporation
5.0
2004-10-18 CVE-2004-1606 Remote vulnerability in Best Software SalesLogix
slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.
network
low complexity
best-software saleslogix-corporation
6.4
2004-10-14 CVE-2004-1605 Remote vulnerability in Best Software SalesLogix
SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.
network
low complexity
best-software saleslogix-corporation
7.5