Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2005-3818
Description:Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-3818
BugTraq ID: 15562
http://www.securityfocus.com/bid/15562
Bugtraq: 20051124 Advisory 23/2005: vTiger multiple vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/417730/30/0/threaded
http://www.hardened-php.net/advisory_232005.105.html
http://www.osvdb.org/21227
http://www.osvdb.org/21228
http://www.osvdb.org/21229
http://www.osvdb.org/21230
http://securitytracker.com/id?1015271
http://secunia.com/advisories/17693
http://www.vupen.com/english/advisories/2005/2569
XForce ISS Database: vtiger-multiple-fields-xss(23362)
https://exchange.xforce.ibmcloud.com/vulnerabilities/23362
XForce ISS Database: vtiger-rss-xss(23363)
https://exchange.xforce.ibmcloud.com/vulnerabilities/23363




© 1998-2025 E-Soft Inc. All rights reserved.