vendor:
CRM
by:
Jerzy Kramarz
7,5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: CRM
Affected Version From: Vtiger 5.4.0
Affected Version To: Vtiger 6.0.0 Security patch 1
Patch Exists: YES
Related CWE: CVE-2014-1222
CPE: a:vtiger:vtiger_crm:6.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Local File Inclusion Vulnerability in Vtiger CRM 6.0 RC
A local file inclusion vulnerability was discovered in the ‘kcfinder’ component of the vtiger CRM 6.0 RC. This could be exploited to include arbitrary files via directory traversal sequences and subsequently disclose contents of arbitrary files. The following request is a Proof-of-Concept for retrieving /etc/passwd file from remote system.
Mitigation:
In order to exploit this vulnerability an attacker has to be authenticated.