← Back

Saleslogix Corporation

saleslogix_corporation

8 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Saleslogix
saleslogix

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Saleslogix Corporation
1Saleslogix
Apr 16, 2026
Oct 18, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.
2Best Software
Saleslogix Corporation
2Saleslogix
Saleslogix
Apr 16, 2026
Oct 18, 2004
N/A· v4
N/A· v3
5.1 MEDIUM· v2
SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-th...Show more
SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port 1707.Show less
2Best Software
Saleslogix Corporation
2Saleslogix
Saleslogix
Apr 16, 2026
Oct 18, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath va...Show more
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.Show less
2Best Software
Saleslogix Corporation
2Saleslogix
Saleslogix
Apr 16, 2026
Oct 18, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
2Best Software
Saleslogix Corporation
2Saleslogix
Saleslogix
Apr 16, 2026
Oct 18, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.
2Best Software
Saleslogix Corporation
2Saleslogix
Saleslogix
Apr 16, 2026
Oct 18, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.
2Best Software
Saleslogix Corporation
2Saleslogix
Saleslogix
Apr 16, 2026
Oct 18, 2004
N/A· v4
N/A· v3
6.4 MEDIUM· v2
slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.
2Best Software
Saleslogix Corporation
2Saleslogix
Saleslogix
Apr 16, 2026
Oct 14, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.