CVE-2004-1226

SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to gain sensitive information via certain requests to scripts that contain invalid input, which reveals the path in an error message, as demonstrated using phprint.php with an empty module parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:50

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=110295433323795&w=2 - () http://marc.info/?l=bugtraq&m=110295433323795&w=2 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/18447 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/18447 -

Information

Published : 2005-01-10 05:00

Updated : 2024-11-20 23:50


NVD link : CVE-2004-1226

Mitre link : CVE-2004-1226

CVE.ORG link : CVE-2004-1226


JSON object : View

Products Affected

sugarcrm

  • sugarcrm