CVE-2004-1228
Last modified
CVE-2004-1228 is a vulnerability of currently unknown severity. The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sugarcrm | Sugar Sales | <= 2.0.1c |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1228?
How severe is CVE-2004-1228?
How do I fix CVE-2004-1228?
Are you affected by CVE-2004-1228?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
