Best Software's vulnerability footprint centers on SalesLogix, a customer relationship management platform deployed across small and mid-market sales organizations. The recurring exposure reflects application-layer complexity inherent to CRM systems, with disclosures primarily categorized under broad classification schemes; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Best Software over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1608HIGH SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation. | Oct 18, 2004 | 7.5 | 24 | NO | NO |
CVE-2004-1605HIGH SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator. | Oct 14, 2004 | 7.5 | 24 | NO | NO |
CVE-2004-1607MEDIUM slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the p | Oct 18, 2004 | 5.0 | 20 | NO | NO |
CVE-2004-1610HIGH SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.A | Oct 18, 2004 | 7.5 | 20 | NO | NO |
CVE-2004-1606MEDIUM slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the E | Oct 18, 2004 | 6.4 | 18 | NO | NO |
CVE-2004-1609MEDIUM SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access. | Oct 18, 2004 | 5.0 | 15 | NO | NO |
CVE-2004-1611MEDIUM SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the se | Oct 18, 2004 | 5.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Best Software.
Media articles that mention a CVE ID that affects a product developed by Best Software — matched by CVE ID, not by vendor name.