CVE-2004-1612

Properties

Published:
17.10.2004
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:N/I:C/A:N/B:N) Approximated
    Product:
    SalesLogix Corporation: SalesLogix

    Vulnerability description

    Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.

    References:

    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109811852218478&w=2
    BID: http://www.securityfocus.com/bid/11450
    SECUNIA: http://secunia.com/advisories/12883
    XF: http://xforce.iss.net/xforce/xfdb/17765
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109811852218478&w=2