CVE-2008-2045

Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sugarcrm:sugarcrm:4.5.1:*:community_edition:*:*:*:*:*
cpe:2.3:a:sugarcrm:sugarcrm:5.0.0:*:community_edition:*:*:*:*:*

History

No history.

Information

Published : 2008-05-01 19:05

Updated : 2023-12-10 10:51


NVD link : CVE-2008-2045

Mitre link : CVE-2008-2045

CVE.ORG link : CVE-2008-2045


JSON object : View

Products Affected

sugarcrm

  • sugarcrm
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')