Multiple directory traversal vulnerabilities in index.php in vTiger CRM 4.2...
Vulnerability Description
Multiple directory traversal vulnerabilities in index.php in vTiger CRM 4.2 and earlier allow remote attackers to read or include arbitrary files, an ultimately execute arbitrary PHP code, via .. (dot dot) and null byte ("%00") sequences in the (1) module parameter and (2) action parameter in the Leads module, as also demonstrated by injecting PHP code into log messages and accessing the log file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-3820
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/417711/30/0/threaded
- http://www.securityfocus.com/bid/15569
- http://www.vupen.com/english/advisories/2005/2569
- http://www.hardened-php.net/advisory_232005.105.html
- http://www.securityfocus.com/bid/15562
- http://securitytracker.com/id?1015271
- http://www.securityfocus.com/archive/1/417730/30/0/threaded
- http://securitytracker.com/id?1015274
- http://marc.info/?l=full-disclosure&m=113290708121951&w=2
- http://secunia.com/advisories/17693
More from vtiger
View All →Affected Vendor
vtiger
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.