Vulnerability Details CVE-2004-1225
SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a DetailView action to index.php, and record parameters in other functionality.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.9%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2004-1225
-
cpe:2.3:a:sugarcrm:sugarcrm:1.0
-
cpe:2.3:a:sugarcrm:sugarcrm:1.0f
-
cpe:2.3:a:sugarcrm:sugarcrm:1.0g
-
cpe:2.3:a:sugarcrm:sugarcrm:1.1
-
cpe:2.3:a:sugarcrm:sugarcrm:1.1a
-
cpe:2.3:a:sugarcrm:sugarcrm:1.1b
-
cpe:2.3:a:sugarcrm:sugarcrm:1.1c
-
cpe:2.3:a:sugarcrm:sugarcrm:1.1d
-
cpe:2.3:a:sugarcrm:sugarcrm:1.1e
-
cpe:2.3:a:sugarcrm:sugarcrm:1.1f
-
cpe:2.3:a:sugarcrm:sugarcrm:1.5d
-
cpe:2.3:a:sugarcrm:sugarcrm:2.0.1
-
cpe:2.3:a:sugarcrm:sugarcrm:2.0.1a