Results 1 to 2 of 2

Thread: SugarCRM Remote Code Execution exploit and how to fix?

  1. #1
    boratti is offline Member
    Join Date
    Nov 2007
    Location
    Istanbul, Turkey
    Posts
    8

    Default SugarCRM Remote Code Execution exploit and how to fix?

    Hi all,

    I saw an exploit at http://www.ush.it/team/ush/hack-sugarcrm_520e/adv.txt for SugarCRM version (5.2.0e and earlier).
    SugarCRM vendors have adviced to upgrade 5.2.0f.

    How can we fix this bug without upgrade?

    Best Regards.

  2. #2
    boratti is offline Member
    Join Date
    Nov 2007
    Location
    Istanbul, Turkey
    Posts
    8

    Default Re: SugarCRM Remote Code Execution exploit and how to fix?

    I fixed the problem copying the function "safeAttachmentName" from email.php (version 5.2.0f) to earlier version (5.2.0a).

    Good weeks.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Accessing sugarcrm database at remote host
    By sagarladdha in forum Help
    Replies: 9
    Last Post: 2009-05-11, 12:58 PM
  2. Need Remote SugarCRM Programmer $30.00 per hour
    By Pearl in forum Classifieds
    Replies: 7
    Last Post: 2008-06-26, 05:10 PM
  3. Replies: 7
    Last Post: 2008-06-26, 04:49 PM
  4. RESOLVED: Using a remote MySQL database with SugarCRM
    By cosjef in forum General Discussion
    Replies: 0
    Last Post: 2006-02-04, 05:35 AM
  5. need code for remote recursive chmod for modules
    By wookie in forum Feature Requests
    Replies: 3
    Last Post: 2005-07-31, 01:53 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •