CVE-2005-4087
Sugar Suite < 4.0 beta - Remote Code Execution via acceptDecline.php beanFiles Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-4087. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets a remote code execution vulnerability in Sugar Suite Open Source <= 4.0 beta. It allows an attacker to execute arbitrary commands by manipulating the 'beanFiles' parameter in the 'acceptDecline.php' script.
Description
PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to execute arbitrary PHP code via a URL in the beanFiles array parameter.
Exploits (2)
This exploit targets a remote code execution vulnerability in Sugar Suite Open Source <= 4.0 beta. It allows an attacker to execute arbitrary commands by manipulating the 'beanFiles' parameter in the 'acceptDecline.php' script.
This exploit targets a remote code execution vulnerability in Sugar Suite Open Source <= 4.0 beta by leveraging a file inclusion flaw in 'acceptDecline.php'. It first uploads a malicious PHP file via a remote URL and then executes arbitrary commands through the uploaded file.