vendor:
SalesLogix
by:
Carl Livitt
7.5
CVSS
HIGH
Arbitrary File Creation
22
CWE
Product Name: SalesLogix
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2004
Arbitrary File Creation in Best Software SalesLogix
The vulnerability allows an attacker to create arbitrary files on the filesystem of the Best Software SalesLogix server by abusing the ProcessQueueFile command. By using directory traversal, the attacker can escape from the Queue directory and write anywhere on the server's filesystem.
Mitigation:
Apply the necessary patches or updates provided by the vendor. Restrict access to the server and implement proper input validation to prevent SQL injection attacks.