The Install Scripts In Sugarcrm Sugar Sales 2.0 vulnerability report
vulnerabilities.aspcode.net
Phase:
The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.
References
BUGTRAQ:Monday, December 13, 2004 SugarSales Multiple Vulnerabilities | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110295433323795&w=2 | XF:sugar-sales-password-plaintext(18449) | URL:http://xforce.iss.net/xforce/xfdb/18449
Votes:
Assigned (Tuesday, December 14, 2004)
Comments:
None (candidate not yet proposed)
F7:
Tagged as
administrative
installation
attackers
cleartext
changing
password
SugarCRM
database
settings
default
scripts
install
removed
earlier
service
allows
denial
obtain
cause
Sugar
after
Sales
MySQL
which
201c
form
not