Best Software
best_software
7 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Best Software Saleslogix Corporation2Saleslogix SaleslogixApr 16, 2026 Oct 18, 2004 N/A· v4 N/A· v3 5.1 MEDIUM· v2 SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-th...Show more |
2Best Software Saleslogix Corporation2Saleslogix SaleslogixApr 16, 2026 Oct 18, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath va...Show more |
2Best Software Saleslogix Corporation2Saleslogix SaleslogixApr 16, 2026 Oct 18, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access. |
2Best Software Saleslogix Corporation2Saleslogix SaleslogixApr 16, 2026 Oct 18, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation. |
2Best Software Saleslogix Corporation2Saleslogix SaleslogixApr 16, 2026 Oct 18, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message. |
2Best Software Saleslogix Corporation2Saleslogix SaleslogixApr 16, 2026 Oct 18, 2004 N/A· v4 N/A· v3 6.4 MEDIUM· v2 slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie. |
2Best Software Saleslogix Corporation2Saleslogix SaleslogixApr 16, 2026 Oct 14, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator. |