CyberSec.Space Logo
CVEブラウザに戻る

CVE-2004-1225

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0030%
EPSS Percentile40.02th
Published2005年1月10日
Last Modified2026年4月16日

Vulnerability Description

SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a DetailView action to index.php, and record parameters in other functionality.

Affected Platforms (CPE)

📦
Sugarcrm

Sugarcrm

= 1.0
📦
Sugarcrm

Sugarcrm

= 1.0f
📦
Sugarcrm

Sugarcrm

= 1.0g
📦
Sugarcrm

Sugarcrm

= 1.1
📦
Sugarcrm

Sugarcrm

= 1.1a
📦
Sugarcrm

Sugarcrm

= 1.1b
📦
Sugarcrm

Sugarcrm

= 1.1c
📦
Sugarcrm

Sugarcrm

= 1.1d
📦
Sugarcrm

Sugarcrm

= 1.1e
📦
Sugarcrm

Sugarcrm

= 1.1f
📦
Sugarcrm

Sugarcrm

= 1.5d
📦
Sugarcrm

Sugarcrm

= 2.0.1
📦
Sugarcrm

Sugarcrm

= 2.0.1a

References & Advisories

関連する脆弱性情報