Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2005-3820
Description:Multiple directory traversal vulnerabilities in index.php in vTiger CRM 4.2 and earlier allow remote attackers to read or include arbitrary files, an ultimately execute arbitrary PHP code, via .. (dot dot) and null byte ("%00") sequences in the (1) module parameter and (2) action parameter in the Leads module, as also demonstrated by injecting PHP code into log messages and accessing the log file.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-3820
BugTraq ID: 15562
http://www.securityfocus.com/bid/15562
BugTraq ID: 15569
http://www.securityfocus.com/bid/15569
Bugtraq: 20051124 Advisory 23/2005: vTiger multiple vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/417730/30/0/threaded
Bugtraq: 20051125 SEC Consult SA-20051125-0 :: More Vulnerabilities in vTiger CRM (Google Search)
http://www.securityfocus.com/archive/1/417711/30/0/threaded
http://marc.info/?l=full-disclosure&m=113290708121951&w=2
http://www.hardened-php.net/advisory_232005.105.html
http://securitytracker.com/id?1015271
http://securitytracker.com/id?1015274
http://secunia.com/advisories/17693
http://www.vupen.com/english/advisories/2005/2569




© 1998-2025 E-Soft Inc. All rights reserved.