Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2146

Опубликовано: 22 июн. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6

Описание

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

РелизСтатусПримечание
dapper

ignored

devel

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

lucid

DNE

upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 92%
0.08739
Низкий

6 Medium

CVSS2

Связанные уязвимости

nvd
больше 16 лет назад

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

debian
больше 16 лет назад

Unrestricted file upload vulnerability in the Compose Email feature in ...

github
почти 4 года назад

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

EPSS

Процентиль: 92%
0.08739
Низкий

6 Medium

CVSS2