CVE

Id
52745  
CVE No.
CVE-2011-4833  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0beta1 allow remote attackers to execute arbitrary SQL commands via the (1) where and (2) order parameters in a get_full_list action to index.php.  
Phase
Assigned (20111214)  
Votes
None (candidate not yet proposed)  
Comments