CVE-2004-1607

Properties

Published:
17.10.2004
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:C/I:N/A:N/B:N) Approximated
    Product:
    Best Software: SalesLogix

    Vulnerability description

    slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.

    References:

    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109811852218478&w=2
    BID: http://www.securityfocus.com/bid/11450
    SECUNIA: http://secunia.com/advisories/12883
    XF: http://xforce.iss.net/xforce/xfdb/17751
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109811852218478&w=2