CVE-2004-1225
SugarCRM Sugar Sales < 2.0.1a - SQL Injection via Record Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1225. PoCs published by GulfTech Security.
AI-analyzed exploit summary The provided text describes a vulnerability in SugarCRM involving insufficient input sanitization, leading to SQL injection via the 'record' parameter in the 'index.php' file. It lacks executable exploit code but outlines the attack vector.
Description
SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a DetailView action to index.php, and record parameters in other functionality.
Exploits (1)
The provided text describes a vulnerability in SugarCRM involving insufficient input sanitization, leading to SQL injection via the 'record' parameter in the 'index.php' file. It lacks executable exploit code but outlines the attack vector.