OSVDB ID: 85078

Title: SugarCRM Logging Functionality Log File Rename Arbitrary Code Execution

Info

Disclosure

Aug 30, 2012

Discovery

Unknown

Dates

Exploit

Aug 30, 2012

Solution

Aug 24, 2012

Description

SugarCRM contains a flaw related to the logging functionality that may allow a remote attacker to execute arbitrary code. The issue is due to the administrator being able to specify any name for a log file, including one with a .php extension. By renaming the file and injecting log content, the log can be called directly to execute arbitrary PHP code.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Public
Disclosure: Vendor Verified, Third-party Verified, Coordinated Disclosure
OSVDB: Authentication Required, Web Related

Solution

Upgrade to version 6.5.3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

SugarCRM Inc.

SugarCRM

6.5.2

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/85078