Vulnerability Details CVE-2004-1610
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.7%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2004-1610
-
cpe:2.3:a:best_software:saleslogix:*
-
cpe:2.3:a:saleslogix_corporation:saleslogix:2000.0