![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2005-3823 |
Description: | The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2005-3823 BugTraq ID: 15569 http://www.securityfocus.com/bid/15569 Bugtraq: 20051125 SEC Consult SA-20051125-0 :: More Vulnerabilities in vTiger CRM (Google Search) http://www.securityfocus.com/archive/1/417711/30/0/threaded http://marc.info/?l=full-disclosure&m=113290708121951&w=2 http://securitytracker.com/id?1015274 http://secunia.com/advisories/17693 http://www.vupen.com/english/advisories/2005/2569 |