Show filters
144 Total Results
Displaying 51-60 of 144
Sort by:
Attacker Value
Unknown
CVE-2013-3591
Disclosure Date: February 07, 2020 (last updated February 21, 2025)
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2015-6000
Disclosure Date: February 06, 2020 (last updated February 21, 2025)
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in test/logo/.
0
Attacker Value
Unknown
CVE-2013-3215
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
0
Attacker Value
Unknown
CVE-2013-3212
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
0
Attacker Value
Unknown
CVE-2013-3214
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
0
Attacker Value
Unknown
CVE-2020-7226
Disclosure Date: January 24, 2020 (last updated February 21, 2025)
CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
0
Attacker Value
Unknown
CVE-2019-20085
Disclosure Date: December 30, 2019 (last updated November 27, 2024)
TVT NVMS-1000 devices allow GET /.. Directory Traversal
0
Attacker Value
Unknown
CVE-2013-4982
Disclosure Date: December 27, 2019 (last updated November 27, 2024)
AVTECH AVN801 DVR has a security bypass via the administration login captcha
0
Attacker Value
Unknown
CVE-2019-19202
Disclosure Date: November 21, 2019 (last updated November 27, 2024)
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.
0
Attacker Value
Unknown
CVE-2019-13379
Disclosure Date: July 07, 2019 (last updated November 27, 2024)
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.
0