CVE

Id
10038  
CVE No.
CVE-2004-1610  
Status
Candidate  
Description
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.  
Phase
Assigned (20050220)  
Votes
None (candidate not yet proposed)  
Comments