FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-5289

This CVE name corresponds to:

Entered Topic
2006-10-15 vtiger -- multiple remote file inclusion vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-5289
Phase Assigned(20061013)

Description

Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the calpath parameter to (1) modules/Calendar/admin/update.php, (2) modules/Calendar/admin/scheme.php, or (3) modules/Calendar/calendar.php.

References

Source Reference
BUGTRAQ 20061009 [ECHO_ADV_54$2006]vtiger CRM <=4.2 (calpath) Multiple Remote File Inclusion Vulnerability
MISC http://advisories.echo.or.id/adv/adv54-theday-2006.txt
MILW0RM 2508
BID 20435
SREASON 1722
XF vtiger-update-file-include(29416)