CVE-2009-2146
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 21%
from disclosure to weapon0 days
Published on NVDJun 22
1st PoCJun 15
exploitation probability
21%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/8949⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.