Show filters
145 Total Results
Displaying 101-110 of 145
Sort by:
Attacker Value
Unknown

CVE-2009-3248

Disclosure Date: September 18, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.
0
Attacker Value
Unknown

CVE-2009-3250

Disclosure Date: September 18, 2009 (last updated October 04, 2023)
The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.
0
Attacker Value
Unknown

CVE-2009-3251

Disclosure Date: September 18, 2009 (last updated October 04, 2023)
include/utils/ListViewUtils.php in vtiger CRM before 5.1.0 allows remote authenticated users to bypass intended access restrictions and read the (1) visibility, (2) location, and (3) recurrence fields of a calendar via a custom view.
0
Attacker Value
Unknown

CVE-2009-2024

Disclosure Date: June 09, 2009 (last updated October 04, 2023)
Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain usernames and passwords via a direct request for zHk8dEes3.txt.
0
Attacker Value
Unknown

CVE-2008-3939

Disclosure Date: September 05, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
0
Attacker Value
Unknown

CVE-2008-3101

Disclosure Date: September 03, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the parenttab parameter in an index action to the Products module, as reachable through index.php; (2) the user_password parameter in an Authenticate action to the Users module, as reachable through index.php; or (3) the query_string parameter in a UnifiedSearch action to the Home module, as reachable through index.php.
0
Attacker Value
Unknown

CVE-2008-3458

Disclosure Date: August 04, 2008 (last updated October 04, 2023)
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.
0
Attacker Value
Unknown

CVE-2008-1142

Disclosure Date: April 07, 2008 (last updated October 04, 2023)
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
0
Attacker Value
Unknown

CVE-2007-5993

Disclosure Date: November 15, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Visionary Technology in Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote attackers to inject arbitrary web script or HTML via the searchtype parameter.
0
Attacker Value
Unknown

CVE-2007-3601

Disclosure Date: July 06, 2007 (last updated October 04, 2023)
vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users' calendar activities via a (1) home page or (2) event list view.
0