CVE-2010-3910

Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM before 5.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang_crm parameter to phprint.php or (2) the current_language parameter in an Accounts Import action to graph.php.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
vtigervtiger_crm
𝑥
≤ 5.2.0
vtigervtiger_crm
1.0
vtigervtiger_crm
2.0
vtigervtiger_crm
2.0.1
vtigervtiger_crm
2.1
vtigervtiger_crm
3.0
vtigervtiger_crm
3.0:beta
vtigervtiger_crm
3.2
vtigervtiger_crm
4.0
vtigervtiger_crm
4.0.1
vtigervtiger_crm
4.2
vtigervtiger_crm
4.2
vtigervtiger_crm
4.2.4
vtigervtiger_crm
5.0.0
vtigervtiger_crm
5.0.2
vtigervtiger_crm
5.0.3
vtigervtiger_crm
5.0.4
vtigervtiger_crm
5.0.4:rc
vtigervtiger_crm
5.1.0
vtigervtiger_crm
5.1.0:rc
𝑥
= Vulnerable software versions