PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to execute arbitrary PHP code via a URL in the beanFiles array parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/418840 | exploit mailing list |
http://securityreason.com/securityalert/239 | third party advisory |
http://www.securityfocus.com/bid/15760 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/23541 | vdb entry |