CVE-2006-2460
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.0%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 10.01% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- sugarcrm/sugarcrm
- Source
- cve@mitre.org
References
- http://retrogod.altervista.org/sugar_suite_42_incl_xpl.htmlExploit
- http://secunia.com/advisories/20072Vendor Advisory
- http://securityreason.com/securityalert/921
- http://securitytracker.com/id?1016087Exploit
- http://www.osvdb.org/25532
- http://www.securityfocus.com/archive/1/434009/100/0/threaded
- http://www.securityfocus.com/bid/17987Exploit
- http://www.vupen.com/english/advisories/2006/1791
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26451
- https://www.exploit-db.com/exploits/1785
- http://retrogod.altervista.org/sugar_suite_42_incl_xpl.htmlExploit
- http://secunia.com/advisories/20072Vendor Advisory
- http://securityreason.com/securityalert/921
- http://securitytracker.com/id?1016087Exploit
- http://www.osvdb.org/25532
- http://www.securityfocus.com/archive/1/434009/100/0/threaded
- http://www.securityfocus.com/bid/17987Exploit
- http://www.vupen.com/english/advisories/2006/1791
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26451
- https://www.exploit-db.com/exploits/1785
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.