SugarCRM Inc.

Short Name: [None Entered]
Previous Names: [None Entered]
URL: [None Entered]
Email: [None Entered]
Security URL: [None Entered]
Security Email: [None Entered]
Knowledge Base: [None Entered]
Notes: [No Notes]

Vulnerabilities by Vendor Product

SugarCRM Inc.

SugarCRM Inc.
Sugar Sales Watch-list
2.0
OSVDB ID: 12738 Sugar Sales index.php Arbitrary Command Execution
SugarCRM Watch-list
1.1e
OSVDB ID: 9271 SugarCRM Unspecified Login Authentication
1.1d
OSVDB ID: 9271 SugarCRM Unspecified Login Authentication
1.1c
OSVDB ID: 9271 SugarCRM Unspecified Login Authentication
1.1b
OSVDB ID: 9271 SugarCRM Unspecified Login Authentication
1.1a
OSVDB ID: 9271 SugarCRM Unspecified Login Authentication
1.0x
OSVDB ID: 9271 SugarCRM Unspecified Login Authentication
2.0
OSVDB ID: 12120 SugarCRM Multiple Module XSS
OSVDB ID: 12228 SugarCRM Direct Script Call XSS
OSVDB ID: 12229 SugarCRM Multiple Module record Parameter SQL Injection
OSVDB ID: 12230 SugarCRM Multiple Module Traversal Arbitrary File Access
OSVDB ID: 13269 SugarCRM Module Path Disclosure
2.0.1
OSVDB ID: 12120 SugarCRM Multiple Module XSS
OSVDB ID: 12228 SugarCRM Direct Script Call XSS
OSVDB ID: 12229 SugarCRM Multiple Module record Parameter SQL Injection
OSVDB ID: 12230 SugarCRM Multiple Module Traversal Arbitrary File Access
OSVDB ID: 13269 SugarCRM Module Path Disclosure
1.5
OSVDB ID: 12120 SugarCRM Multiple Module XSS
OSVDB ID: 12228 SugarCRM Direct Script Call XSS
OSVDB ID: 12229 SugarCRM Multiple Module record Parameter SQL Injection
OSVDB ID: 12230 SugarCRM Multiple Module Traversal Arbitrary File Access
OSVDB ID: 13269 SugarCRM Module Path Disclosure
5.2 i
OSVDB ID: 58461 SugarCRM Unspecified XSS
5.2 h
OSVDB ID: 58461 SugarCRM Unspecified XSS
5.2 g
OSVDB ID: 58461 SugarCRM Unspecified XSS
OSVDB ID: 57393 SugarCRM Unspecified SQL Injection
5.0 l
OSVDB ID: 58461 SugarCRM Unspecified XSS
5.0 k
OSVDB ID: 58461 SugarCRM Unspecified XSS
OSVDB ID: 57393 SugarCRM Unspecified SQL Injection
4.5.1 p
OSVDB ID: 58461 SugarCRM Unspecified XSS
4.5.1 o
OSVDB ID: 58461 SugarCRM Unspecified XSS
OSVDB ID: 57393 SugarCRM Unspecified SQL Injection
5.5.0a
OSVDB ID: 63025 SugarCRM Document Creation Document Name XSS
5.2.0l
OSVDB ID: 63025 SugarCRM Document Creation Document Name XSS
5.2.x
OSVDB ID: 63025 SugarCRM Document Creation Document Name XSS
5.5.x
OSVDB ID: 63025 SugarCRM Document Creation Document Name XSS
5.2.0j
OSVDB ID: 60507 SugarCRM index.php file Parameter Remote File Inclusion
OSVDB ID: 60505 SugarCRM index.php current_query_by_page Parameter SQL Injection
OSVDB ID: 60506 SugarCRM Delete Functionality Access Restriction Weakness Arbitrary File Deletion
OSVDB ID: 60508 SugarCRM Backup Functionality Access Restriction Weakness
OSVDB ID: 60509 SugarCRM Upgrade Wizard ZIP File Upload Arbitrary PHP Code Execution
OSVDB ID: 60510 SugarCRM on Windows .htaccess Direct Request Arbitrary File Access
5.5.0.RC2
OSVDB ID: 60507 SugarCRM index.php file Parameter Remote File Inclusion
OSVDB ID: 60505 SugarCRM index.php current_query_by_page Parameter SQL Injection
OSVDB ID: 60506 SugarCRM Delete Functionality Access Restriction Weakness Arbitrary File Deletion
OSVDB ID: 60508 SugarCRM Backup Functionality Access Restriction Weakness
OSVDB ID: 60509 SugarCRM Upgrade Wizard ZIP File Upload Arbitrary PHP Code Execution
OSVDB ID: 60510 SugarCRM on Windows .htaccess Direct Request Arbitrary File Access
6.3.1
OSVDB ID: 83361 SugarCRM Multiple Script unserialize() Function Arbitrary PHP Code Execution
6.5.2
OSVDB ID: 85111 SugarCRM cache/include/externalAPI.cache.js File Direct Request Path Disclosure
OSVDB ID: 85112 SugarCRM vcal_server.php Username / Email Address Enumeration
OSVDB ID: 85081 SugarCRM ical_server.php User Schedule Disclosure
OSVDB ID: 85080 SugarCRM index.php File Handling XSS
OSVDB ID: 85068 SugarCRM index.php group Parameter SQL Injection
OSVDB ID: 85078 SugarCRM Logging Functionality Log File Rename Arbitrary Code Execution
6.5.2
6.5.2
OSVDB ID: 85079 SugarCRM index.php JSON Query Parsing Password Hash Disclosure
6.5.2
6.5.2
6.5.2
6.5.2
Sugar Suite Watch-list
4.2.0a
OSVDB ID: 25532 Sugar Suite Multiple Script sugarEntry Global Parameter Remote File Inclusion



The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use