Логотип exploitDog
bind:CVE-2009-2146
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2009-2146

Количество 4

Количество 4

ubuntu логотип

CVE-2009-2146

больше 16 лет назад

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2009-2146

больше 16 лет назад

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2009-2146

больше 16 лет назад

Unrestricted file upload vulnerability in the Compose Email feature in ...

CVSS2: 6
EPSS: Низкий
github логотип

GHSA-fw9h-q663-phqj

почти 4 года назад

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2009-2146

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

CVSS2: 6
9%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-2146

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

CVSS2: 6
9%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-2146

Unrestricted file upload vulnerability in the Compose Email feature in ...

CVSS2: 6
9%
Низкий
больше 16 лет назад
github логотип
GHSA-fw9h-q663-phqj

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

9%
Низкий
почти 4 года назад

Уязвимостей на страницу