This Metasploit module exploits a php unserialize() vulnerability in SugarCRM versions 6.3.1 and below which could be abused to allow authenticated SugarCRM users to execute arbitrary code with the permissions of the webserver. The dangerous unserialize() exists in the 'include/MVC/View/views/view.list.php' script, which is called with user controlled data from the 'current_query_by_page' parameter. The exploit abuses the __destruct() method from the SugarTheme class to write arbitrary PHP code to a 'pathCache.php' on the web root.
7d01dafa74c844c1735769142b67e3ac
SugarCRM CE versions 6.3.1 and below suffer from an unserialize() PHP code execution vulnerability.
4e1ff130d3e0520df25511c645de85f6