SugarSales Multiple Remote Vulnerabilities
BID:11896
Info
SugarSales Multiple Remote Vulnerabilities
| Bugtraq ID: | 11896 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2004 12:00AM |
| Updated: | Dec 13 2004 12:00AM |
| Credit: | "Daniel Fabian" <[email protected]> disclosed these vulnerabilities. |
| Vulnerable: |
SugarCRM SugarSales 2.0.1 c SugarCRM SugarCRM 2.0.1 a SugarCRM SugarCRM 2.0.1 SugarCRM SugarCRM 1.5 d SugarCRM SugarCRM 1.1 f SugarCRM SugarCRM 1.1 e SugarCRM SugarCRM 1.1 d SugarCRM SugarCRM 1.1 c SugarCRM SugarCRM 1.1 b SugarCRM SugarCRM 1.1 a SugarCRM SugarCRM 1.1 SugarCRM SugarCRM 1.0 g SugarCRM SugarCRM 1.0 f SugarCRM SugarCRM 1.0 |
| Not Vulnerable: | |
Discussion
SugarSales Multiple Remote Vulnerabilities
Multiple remote vulnerabilities are reported to exist in SugarSales.
The first reported issue is an SQL injection vulnerability. This vulnerability is due to a lack of proper input-validation by the application, prior to utilizing attacker-supplied data in and SQL query.
This vulnerability is reported to exist in versions prior to 2.0.1a.
The next issue is reportedly a directory traversal vulnerability. This vulnerability is also due to a lack of proper input-validation by the application.
The last reported issue is a remote denial of service and information disclosure vulnerability.
The directory traversal and installation script vulnerabilities reportedly exist in all current versions of SugarSales.
These vulnerabilities may be related to the issues disclosed in BID 11740.
Multiple remote vulnerabilities are reported to exist in SugarSales.
The first reported issue is an SQL injection vulnerability. This vulnerability is due to a lack of proper input-validation by the application, prior to utilizing attacker-supplied data in and SQL query.
This vulnerability is reported to exist in versions prior to 2.0.1a.
The next issue is reportedly a directory traversal vulnerability. This vulnerability is also due to a lack of proper input-validation by the application.
The last reported issue is a remote denial of service and information disclosure vulnerability.
The directory traversal and installation script vulnerabilities reportedly exist in all current versions of SugarSales.
These vulnerabilities may be related to the issues disclosed in BID 11740.
Exploit / POC
SugarSales Multiple Remote Vulnerabilities
Example URIs sufficient to exploit these vulnerabilities have been provided:
To log into SugarSales, utilize the username "admin' or 1=1 -- " with any password.
To disclose the contents of potentially sensitive files:
http://www.example.com/sugarcrm/modules/Users/Login.php?theme=/../../../etc/hosts%00
http://www.example.com/sugarcrm/modules/Calls/index.php?theme=/../../../etc/hosts%00
Example URIs sufficient to exploit these vulnerabilities have been provided:
To log into SugarSales, utilize the username "admin' or 1=1 -- " with any password.
To disclose the contents of potentially sensitive files:
http://www.example.com/sugarcrm/modules/Users/Login.php?theme=/../../../etc/hosts%00
http://www.example.com/sugarcrm/modules/Calls/index.php?theme=/../../../etc/hosts%00
Solution / Fix
SugarSales Multiple Remote Vulnerabilities
Solution:
Reportedly, the SQL injection vulnerability has been fixed in version 2.0.1a. The other vulnerabilities however, have reportedly not been fixed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Reportedly, the SQL injection vulnerability has been fixed in version 2.0.1a. The other vulnerabilities however, have reportedly not been fixed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SugarSales Multiple Remote Vulnerabilities
References:
References:
- SugarCRM Homepage (SugarCRM)
- SugarCRM-2.0.1a Release Notes (SugarCRM)
- SugarSales Multiple Vulnerabilities ("Daniel Fabian"
)