SugarCRM Community Edition 'unserialize()' Multiple PHP Code Execution Vulnerabilities
BID:54169
Info
SugarCRM Community Edition 'unserialize()' Multiple PHP Code Execution Vulnerabilities
| Bugtraq ID: | 54169 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0694 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2012 12:00AM |
| Updated: | Jun 27 2012 04:50PM |
| Credit: | EgiX |
| Vulnerable: |
SugarCRM SugarCRM Community Edition 5.0 SugarCRM SugarCRM Community Edition 4.5.1 SugarCRM SugarCRM Community Edition 6.3.0RC1 SugarCRM SugarCRM Community Edition 5.0.0c SugarCRM SugarCRM Community Edition 4.5.1j |
| Not Vulnerable: |
SugarCRM SugarCRM Community Edition 6.4.0 |
Discussion
SugarCRM Community Edition 'unserialize()' Multiple PHP Code Execution Vulnerabilities
SugarCRM Community Edition is prone to multiple remote PHP code-execution vulnerabilities.
An attacker can exploit these issues to inject and execute arbitrary malicious PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
SugarCRM Community Edition versions 6.3.1 and prior are vulnerable.
SugarCRM Community Edition is prone to multiple remote PHP code-execution vulnerabilities.
An attacker can exploit these issues to inject and execute arbitrary malicious PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
SugarCRM Community Edition versions 6.3.1 and prior are vulnerable.
Exploit / POC
SugarCRM Community Edition 'unserialize()' Multiple PHP Code Execution Vulnerabilities
Attackers can exploit these issues using a browser.
The following exploit is available:
Attackers can exploit these issues using a browser.
The following exploit is available:
Solution / Fix
SugarCRM Community Edition 'unserialize()' Multiple PHP Code Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
SugarCRM Community Edition 'unserialize()' Multiple PHP Code Execution Vulnerabilities
References:
References:
- SugarCRM Homepage (SugarCRM)