peter bassill · operator
$ cve CVE-2005-4086 JSON

CVE-2005-4086 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 7.3% (pctl 94)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the beanFiles array parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS7.33% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2005-12-08
Last modified2026-06-16

Affected (1)

VendorProduct
sugarcrmsugar suite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD