Description
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.
Affected products
- saleslogix_corporation / saleslogix2000.0 – 2000.0
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/12883
- MISChttp://www.osvdb.org/10949
- MAILING_LISThttp://marc.info/?l=bugtraq&m=109811852218478&w=2
- MISChttp://securitytracker.com/id?1011769
- MISChttp://www.securityfocus.com/bid/11450
- MISChttp://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/17765