CVE-2006-2460

Sugarcrm - Path Traversal

Title source: rule

Description

Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1785

Scores

EPSS 0.0608
EPSS Percentile 90.8%

Details

Status published
Products (4)
sugarcrm/sugarcrm 3.5
sugarcrm/sugarcrm 4.0
sugarcrm/sugarcrm 4.1
sugarcrm/sugarcrm 4.2
Published May 19, 2006
Tracked Since Feb 18, 2026