Total vulnerabilities in the database
Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM before 5.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang_crm parameter to phprint.php or (2) the current_language parameter in an Accounts Import action to graph.php.
Software | From | Fixed in |
---|---|---|
vtiger / vtiger_crm | 3 | 3.x |
vtiger / vtiger_crm | 5.0.3 | 5.0.3.x |
vtiger / vtiger_crm | - | 5.2.0.x |
vtiger / vtiger_crm | 5.1.0 | 5.1.0.x |
vtiger / vtiger_crm | 2.0.1 | 2.0.1.x |
vtiger / vtiger_crm | 2.0 | 2.0.x |
vtiger / vtiger_crm | 4.2 | 4.2.x |
vtiger / vtiger_crm | 5.0.4 | 5.0.4.x |
vtiger / vtiger_crm | 2.1 | 2.1.x |
vtiger / vtiger_crm | 5.1.0-rc | 5.1.0-rc.x |
vtiger / vtiger_crm | 4 | 4.x |
vtiger / vtiger_crm | 4.0 | 4.0.x |
vtiger / vtiger_crm | 3.0-beta | 3.0-beta.x |
vtiger / vtiger_crm | 3.0 | 3.0.x |
vtiger / vtiger_crm | 4-rc1 | 4-rc1.x |
vtiger / vtiger_crm | 5.0.0 | 5.0.0.x |
vtiger / vtiger_crm | 5.0.2 | 5.0.2.x |
vtiger / vtiger_crm | 3.2 | 3.2.x |
vtiger / vtiger_crm | 5.0.4-rc | 5.0.4-rc.x |
vtiger / vtiger_crm | 1.0 | 1.0.x |
vtiger / vtiger_crm | 4-beta | 4-beta.x |
vtiger / vtiger_crm | 4.2.4 | 4.2.4.x |
vtiger / vtiger_crm | 4.0.1 | 4.0.1.x |