Show filters
144 Total Results
Displaying 51-60 of 144
Sort by:
Attacker Value
Unknown

CVE-2013-3591

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
Attacker Value
Unknown

CVE-2015-6000

Disclosure Date: February 06, 2020 (last updated February 21, 2025)
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in test/logo/.
Attacker Value
Unknown

CVE-2013-3215

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
Attacker Value
Unknown

CVE-2013-3212

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
Attacker Value
Unknown

CVE-2013-3214

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
Attacker Value
Unknown

CVE-2020-7226

Disclosure Date: January 24, 2020 (last updated February 21, 2025)
CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
Attacker Value
Unknown

CVE-2019-20085

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
TVT NVMS-1000 devices allow GET /.. Directory Traversal
Attacker Value
Unknown

CVE-2013-4982

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
AVTECH AVN801 DVR has a security bypass via the administration login captcha
Attacker Value
Unknown

CVE-2019-19202

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.
Attacker Value
Unknown

CVE-2019-13379

Disclosure Date: July 07, 2019 (last updated November 27, 2024)
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.
0