CVE-2010-3909
Vtiger CRM 5.2.0 Code Execution / Cross Site Scripting / Local File Inclusion
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by using the draft save feature in the Compose Mail component to upload a file with a .phtml extension, and then accessing this file via a direct request to the file in the storage/ directory tree.
Vulnerabilidad de la lista negra incompleta en config.template.php en vtiger CRM antes de v5.2.1 permite a usuarios remotos autenticados ejecutar código arbitrario mediante la característica de guardado de borrador en el componente Compose Mail para cargar un archivo con extensión .phtml, y luego acceder a este archivo a través de una solicitud directa al archivo en el almacenamiento / árbol de directorios.
Vtiger CRM 5.2.0 suffers from code execution, cross site scripting and local file inclusion vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-10-12 CVE Reserved
- 2010-11-18 CVE Published
- 2024-08-07 CVE Updated
- 2025-01-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://vtiger.com/blogs/2010/11/16/vtiger-crm-521-is-released | X_refsource_misc | |
http://wiki.vtiger.com/index.php/Vtiger521:Release_Notes | X_refsource_misc | |
http://www.securityfocus.com/archive/1/514846/100/0/threaded | Mailing List | |
http://www.ush.it/team/ush/hack-vtigercrm_520/vtigercrm_520.txt | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/42246 | 2018-10-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | * | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | <= 5.2.0 Search vendor "Vtiger" for product "Vtiger Crm" and version " <= 5.2.0" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 1.0 Search vendor "Vtiger" for product "Vtiger Crm" and version "1.0" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 2.0 Search vendor "Vtiger" for product "Vtiger Crm" and version "2.0" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 2.0.1 Search vendor "Vtiger" for product "Vtiger Crm" and version "2.0.1" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 2.1 Search vendor "Vtiger" for product "Vtiger Crm" and version "2.1" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 3 Search vendor "Vtiger" for product "Vtiger Crm" and version "3" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 3.0 Search vendor "Vtiger" for product "Vtiger Crm" and version "3.0" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 3.0 Search vendor "Vtiger" for product "Vtiger Crm" and version "3.0" | beta |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 3.2 Search vendor "Vtiger" for product "Vtiger Crm" and version "3.2" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 4 Search vendor "Vtiger" for product "Vtiger Crm" and version "4" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 4 Search vendor "Vtiger" for product "Vtiger Crm" and version "4" | beta |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 4 Search vendor "Vtiger" for product "Vtiger Crm" and version "4" | rc1 |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 4.0 Search vendor "Vtiger" for product "Vtiger Crm" and version "4.0" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 4.0.1 Search vendor "Vtiger" for product "Vtiger Crm" and version "4.0.1" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 4.2 Search vendor "Vtiger" for product "Vtiger Crm" and version "4.2" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 4.2 Search vendor "Vtiger" for product "Vtiger Crm" and version "4.2" | validation |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 4.2.4 Search vendor "Vtiger" for product "Vtiger Crm" and version "4.2.4" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 5.0.0 Search vendor "Vtiger" for product "Vtiger Crm" and version "5.0.0" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 5.0.2 Search vendor "Vtiger" for product "Vtiger Crm" and version "5.0.2" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 5.0.3 Search vendor "Vtiger" for product "Vtiger Crm" and version "5.0.3" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 5.0.4 Search vendor "Vtiger" for product "Vtiger Crm" and version "5.0.4" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 5.0.4 Search vendor "Vtiger" for product "Vtiger Crm" and version "5.0.4" | rc |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 5.1.0 Search vendor "Vtiger" for product "Vtiger Crm" and version "5.1.0" | - |
Affected
| ||||||
Vtiger Search vendor "Vtiger" | Vtiger Crm Search vendor "Vtiger" for product "Vtiger Crm" | 5.1.0 Search vendor "Vtiger" for product "Vtiger Crm" and version "5.1.0" | rc |
Affected
|