Best-software
7 CVEs tracked since 2005. Since Feb 2005, none of them reached CISA KEV.
Best-software CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2005-02 | 7 | 0 |
Products
The products that kept showing up in Best-software's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 7 most recently published vulnerabilities affecting Best-software.
- CVE-2004-1609SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.5.0
- CVE-2004-1607slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error m...5.0
- CVE-2004-1606slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.6.4
- CVE-2004-1611SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the...5.1
- CVE-2004-1610SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or ...7.5
- CVE-2004-1605SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.7.5
- CVE-2004-1608SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.7.5
The record
- Peak rank
- #18 in Feb 2005
- Busiest month shown
- Feb 2005, 7 CVEs
- Months with a KEV entry
- 0 since Feb 2005
- Monthly snapshots
- 1 since 2005