vendor:
SalesLogix
by:
Carl Livitt
5.5
CVSS
MEDIUM
Arbitrary File Creation
22
CWE
Product Name: SalesLogix
Affected Version From: SLX 6.1
Affected Version To: SLX 6.1
Patch Exists: NO
Related CWE:
CPE: a:sage:saleslogix:6.1
Platforms Tested:
2004
Arbitrary File Creation for SLX Server 6.1
This exploit abuses the ProcessQueueFile command on SLX 6.1 servers to create arbitrary files on the filesystem of the SLX server. By using directory traversal, it is possible to escape from the Queue directory and write anywhere on the SLX server's filesystem.
Mitigation:
Apply patches or updates provided by the vendor. Limit access to the SLX server to trusted users only.