CVE-2004-1612
SalesLogix 6.1 - Directory Traversal and Arbitrary File Upload via ProcessQueueFile Request
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2004-1612. PoCs published by Carl Livitt.
AI-analyzed exploit summary This exploit abuses the ProcessQueueFile command in Sage SalesLogix 6.1 via directory traversal to create arbitrary files on the server's filesystem. It uploads a local file to a specified path on the target system, limited to files under 4KB.
Description
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.
Exploits (2)
This exploit abuses the ProcessQueueFile command in Sage SalesLogix 6.1 via directory traversal to create arbitrary files on the server's filesystem. It uploads a local file to a specified path on the target system, limited to files under 4KB.
This exploit leverages a directory traversal vulnerability in Sage SalesLogix 6.1's ProcessQueueFile command to create arbitrary files on the server's filesystem. It sends a crafted payload to port 1707, allowing file uploads outside the intended Queue directory.