Back

CVE-2004-1227

Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot) sequences in the (1) module, (2) action, or (3) theme parameters to index.php, (4) the theme parameter to Login.php, and possibly other parameters or scripts.

Published: Jan 10, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
sugarcrm sugar_sales *

GitHub Security Advisory GHSA-gfv8-v4p2-qcf9

Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 4.15%

Top 10% most likely to be exploited

Threat Score 41.2 / 100

Data Sources

NVD EPSS GitHub