ID

VAR-E-201104-0425


EDB ID

35574


TITLE

vTiger CRM 5.2.1 - 'sortfieldsjson.php' Local File Inclusion - PHP webapps Exploit

Trust: 0.6

sources: EXPLOIT-DB: 35574

DESCRIPTION

vTiger CRM 5.2.1 - 'sortfieldsjson.php' Local File Inclusion.. webapps exploit for PHP platform

Trust: 0.6

sources: EXPLOIT-DB: 35574

AFFECTED PRODUCTS

vendor:vtigermodel:crmscope:eqversion:5.2.1

Trust: 1.9

sources: BID: 47263 // EXPLOIT-DB: 35574 // EDBNET: 56739

EXPLOIT

source: https://www.securityfocus.com/bid/47263/info

vtiger CRM is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to obtain potentially sensitive information and execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.

vtiger CRM 5.2.1 is vulnerable; other versions may also be affected.

http://www.example.com/vtigercrm/modules/com_vtiger_workflow/sortfieldsjson.php?module_name=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows%2fwin.ini%00

Trust: 1.0

sources: EXPLOIT-DB: 35574

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 35574

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 35574

TYPE

'sortfieldsjson.php' Local File Inclusion

Trust: 1.0

sources: EXPLOIT-DB: 35574

CREDITS

John Leitch

Trust: 0.6

sources: EXPLOIT-DB: 35574

EXTERNAL IDS

db:BIDid:47263

Trust: 1.9

db:EXPLOIT-DBid:35574

Trust: 1.6

db:EDBNETid:56739

Trust: 0.6

sources: BID: 47263 // EXPLOIT-DB: 35574 // EDBNET: 56739

REFERENCES

url:https://www.securityfocus.com/bid/47263/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/35574/

Trust: 0.6

url:http://www.vtiger.com/

Trust: 0.3

sources: BID: 47263 // EXPLOIT-DB: 35574 // EDBNET: 56739

SOURCES

db:BIDid:47263
db:EXPLOIT-DBid:35574
db:EDBNETid:56739

LAST UPDATE DATE

2022-07-27T09:38:19.959000+00:00


SOURCES UPDATE DATE

db:BIDid:47263date:2011-04-08T00:00:00

SOURCES RELEASE DATE

db:BIDid:47263date:2011-04-08T00:00:00
db:EXPLOIT-DBid:35574date:2011-04-08T00:00:00
db:EDBNETid:56739date:2011-04-08T00:00:00