Back to Database
Status published
High
CVE-2004-1605
SalesLogix 6.1 allows remote attackers to bypass authentication by modifying...
Vulnerability Description
SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1605
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/12883
- http://marc.info/?l=bugtraq&m=109811852218478&w=2
- http://securitytracker.com/id?1011769
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17749
- http://www.securityfocus.com/bid/11450
- http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0661.html
- http://www.osvdb.org/10942
More from best software
View All →CVE-2004-1611
SalesLogix 6.1 does not verify if a user is authenticated...
Medium
5.1
CVE-2004-1610
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which...
High
7.5
CVE-2004-1609
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in...
Medium
5
CVE-2004-1608
SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to...
High
7.5
CVE-2004-1607
slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive...
Medium
5
Affected Vendor
best software
View all reports →Affected Software
saleslogix
Vulnerable Versions:
2000.0
Timeline
Official Publish:
February 20th, 2005
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.