Back

CVE-2005-4087

PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to execute arbitrary PHP code via a URL in the beanFiles array parameter.

Published: Dec 8, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
sugarcrm sugar_suite 3.5
sugarcrm sugar_suite 4.0_beta

GitHub Security Advisory GHSA-xqrv-hxv4-28ph

PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.73%

Top 11% most likely to be exploited

Threat Score 31.1 / 100

Data Sources

NVD EPSS GitHub