
Full Disclosure mailing list archives
[CVE-2014-3244]SugarCRM v6.5.16 rss dashlet LFI via XXE Attack
From: pnig0spnig0s <pnigos () live com>
Date: Tue, 17 Jun 2014 23:48:18 +0000
Product:SugarCRM Description:SugarCRM enables businesses to create extraordinary customer relationships with the most innovative and affordable CRM solution in the market. Version affected:v6.5.16 and less Type:XML External Entity Attack Consequence:Arbitrary Local File Read&Potential RCE Vulnerability Details:http://www.pnigos.com/?p=294Fix Released:This bug has fixed in v6.5.17 Bug was found by pnig0s @ FreeBuf.Com ================================================== Best Regards,pnig0s _______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- [CVE-2014-3244]SugarCRM v6.5.16 rss dashlet LFI via XXE Attack pnig0spnig0s (Jun 18)