Show filters
145 Total Results
Displaying 101-110 of 145
Sort by:
Attacker Value
Unknown
CVE-2009-3248
Disclosure Date: September 18, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.
0
Attacker Value
Unknown
CVE-2009-3250
Disclosure Date: September 18, 2009 (last updated October 04, 2023)
The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.
0
Attacker Value
Unknown
CVE-2009-3251
Disclosure Date: September 18, 2009 (last updated October 04, 2023)
include/utils/ListViewUtils.php in vtiger CRM before 5.1.0 allows remote authenticated users to bypass intended access restrictions and read the (1) visibility, (2) location, and (3) recurrence fields of a calendar via a custom view.
0
Attacker Value
Unknown
CVE-2009-2024
Disclosure Date: June 09, 2009 (last updated October 04, 2023)
Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain usernames and passwords via a direct request for zHk8dEes3.txt.
0
Attacker Value
Unknown
CVE-2008-3939
Disclosure Date: September 05, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
0
Attacker Value
Unknown
CVE-2008-3101
Disclosure Date: September 03, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the parenttab parameter in an index action to the Products module, as reachable through index.php; (2) the user_password parameter in an Authenticate action to the Users module, as reachable through index.php; or (3) the query_string parameter in a UnifiedSearch action to the Home module, as reachable through index.php.
0
Attacker Value
Unknown
CVE-2008-3458
Disclosure Date: August 04, 2008 (last updated October 04, 2023)
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.
0
Attacker Value
Unknown
CVE-2008-1142
Disclosure Date: April 07, 2008 (last updated October 04, 2023)
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
0
Attacker Value
Unknown
CVE-2007-5993
Disclosure Date: November 15, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Visionary Technology in Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote attackers to inject arbitrary web script or HTML via the searchtype parameter.
0
Attacker Value
Unknown
CVE-2007-3601
Disclosure Date: July 06, 2007 (last updated October 04, 2023)
vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users' calendar activities via a (1) home page or (2) event list view.
0