CVE-2011-4833
SugarCRM 6.1-6.1.6 6.2-6.2.3 6.3-6.3.0RC2 6.4-6.4.0beta - SQL Injection via Leads Module Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-4833. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in SugarCRM Community Edition by injecting malicious SQL queries via the 'where' and 'order' parameters in the URL. The PoC retrieves the database version and allows arbitrary SQL execution.
Description
Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0beta1 allow remote attackers to execute arbitrary SQL commands via the (1) where and (2) order parameters in a get_full_list action to index.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in SugarCRM Community Edition by injecting malicious SQL queries via the 'where' and 'order' parameters in the URL. The PoC retrieves the database version and allows arbitrary SQL execution.