SugarSales Multiple Remote Vulnerabilities...

- AV AC AU C I A
发布: 2004-12-13
修订: 2025-04-13

Multiple remote vulnerabilities are reported to exist in SugarSales. The first reported issue is an SQL injection vulnerability. This vulnerability is due to a lack of proper input-validation by the application, prior to utilizing attacker-supplied data in and SQL query. This vulnerability is reported to exist in versions prior to 2.0.1a. The next issue is reportedly a directory traversal vulnerability. This vulnerability is also due to a lack of proper input-validation by the application. The last reported issue is a remote denial of service and information disclosure vulnerability. The directory traversal and installation script vulnerabilities reportedly exist in all current versions of SugarSales. These vulnerabilities may be related to the issues disclosed in BID 11740.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息