VYPR
Unrated severityNVD Advisory· Published Oct 18, 2004· Updated Apr 16, 2026

CVE-2004-1610

CVE-2004-1610

Description

SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.

Affected products

2
  • cpe:2.3:a:best_software:saleslogix:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:best_software:saleslogix:*:*:*:*:*:*:*:*
    • cpe:2.3:a:saleslogix_corporation:saleslogix:2000.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.