CVE-2010-3910
26.11.2010, 20:00
Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM before 5.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang_crm parameter to phprint.php or (2) the current_language parameter in an Accounts Import action to graph.php.
Vendor | Product | Version |
---|---|---|
vtiger | vtiger_crm | 𝑥 ≤ 5.2.0 |
vtiger | vtiger_crm | 1.0 |
vtiger | vtiger_crm | 2.0 |
vtiger | vtiger_crm | 2.0.1 |
vtiger | vtiger_crm | 2.1 |
vtiger | vtiger_crm | 3.0 |
vtiger | vtiger_crm | 3.0:beta |
vtiger | vtiger_crm | 3.2 |
vtiger | vtiger_crm | 4.0 |
vtiger | vtiger_crm | 4.0.1 |
vtiger | vtiger_crm | 4.2 |
vtiger | vtiger_crm | 4.2 |
vtiger | vtiger_crm | 4.2.4 |
vtiger | vtiger_crm | 5.0.0 |
vtiger | vtiger_crm | 5.0.2 |
vtiger | vtiger_crm | 5.0.3 |
vtiger | vtiger_crm | 5.0.4 |
vtiger | vtiger_crm | 5.0.4:rc |
vtiger | vtiger_crm | 5.1.0 |
vtiger | vtiger_crm | 5.1.0:rc |
𝑥
= Vulnerable software versions
References