SugarCRM CE unserialize PHP code execution in multiple files

Overview :
SugarCRM CE <= 6.3.1 contains scripts that use “unserialize()” with user controlled input which allows remote attackers to execute arbitrary PHP code.
Affected Product(s) :
  • SugarCRM CE 6.3.1
Vulnerability Details :
CVE ID : CVE-2012-0694
The vulnerability is caused due to all these scripts using “unserialize()” with user controlled input. This can be exploited to e.g. execute arbitrary PHP code via the “__destruct()” method of the “SugarTheme” class, passing an ad-hoc serialized

Solution :
Vendor fix the issue on his own within 6.4.0 RC1 release

 

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2022-1840 : Home Clean Services Management System Stored Cross-Site Scripting (XSS)

CVE-2022-1840 : Home Clean Services Management System Stored Cross-Site Scripting (XSS)

Description Persistent XSS (or Stored XSS) attack is one of the three major categories of XSS attacks, the others being

CVE-2022-1558 : Multiple Stored Cross-Site Scripting vulnerabilities in WordPress curtain plugin 1.0.2

CVE-2022-1558 : Multiple Stored Cross-Site Scripting vulnerabilities in WordPress curtain plugin 1.0.2

Description Several Cross-Site Scripting vulnerabilities in the Curtain WordPress plugin. Due to these Cross-Site Scripting vulnerabilities, an attacker would be

CVE-2022-AVAST2 : Self-Defense Bypass via Repairing Function

CVE-2022-AVAST2 : Self-Defense Bypass via Repairing Function

Description It was noted that there is security checking to prevent some of the Avast processes from loading of undesired/unsigned