RULE(RULE ID:322695)

Rule General Information
Release Date: 2019-07-08
Rule Name: Best Software SalesLogix 'view' 'id' Parameter SQL Injection Vulnerability (CVE-2004-1612)
Severity:
CVE ID:
Rule Protection Details
Description: Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:11450
http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html
http://marc.info/?l=bugtraq&m=109811852218478&w=2
SecurityTrackerID:1011769
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://support.saleslogix.com/