CVE-2009-3249
Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a ..
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the module parameter to graph.php; or the (2) module or (3) file parameter to include/Ajax/CommonAjax.php, reachable through modules/Campaigns/CampaignsAjax.php, modules/SalesOrder/SalesOrderAjax.php, modules/System/SystemAjax.php, modules/Products/ProductsAjax.php, modules/uploads/uploadsAjax.php, modules/Dashboard/DashboardAjax.php, modules/Potentials/PotentialsAjax.php, modules/Notes/NotesAjax.php, modules/Faq/FaqAjax.php, modules/Quotes/QuotesAjax.php, modules/Utilities/UtilitiesAjax.php, modules/Calendar/ActivityAjax.php, modules/Calendar/CalendarAjax.php, modules/PurchaseOrder/PurchaseOrderAjax.php, modules/HelpDesk/HelpDeskAjax.php, modules/Invoice/InvoiceAjax.php, modules/Accounts/AccountsAjax.php, modules/Reports/ReportsAjax.php, modules/Contacts/ContactsAjax.php, and modules/Portal/PortalAjax.php; and allow remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the step parameter in an Import action to the (4) Accounts, (5) Contacts, (6) HelpDesk, (7) Leads, (8) Potentials, (9) Products, or (10) Vendors module, reachable through index.php and related to modules/Import/index.php and multiple Import.php files.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 9.59% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- vtiger/vtiger crm
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=125060676515670&w=2
- http://secunia.com/advisories/36309Vendor Advisory
- http://securityreason.com/securityalert/8118
- http://www.exploit-db.com/exploits/9450
- http://www.osvdb.org/57239Exploit
- http://www.securityfocus.com/bid/36062Exploit
- http://www.ush.it/2009/08/18/vtiger-crm-504-multiple-vulnerabilities/Exploit
- http://www.ush.it/team/ush/hack-vtigercrm_504/vtigercrm_504.txtExploit
- http://www.vupen.com/english/advisories/2009/2319Vendor Advisory
- http://marc.info/?l=bugtraq&m=125060676515670&w=2
- http://secunia.com/advisories/36309Vendor Advisory
- http://securityreason.com/securityalert/8118
- http://www.exploit-db.com/exploits/9450
- http://www.osvdb.org/57239Exploit
- http://www.securityfocus.com/bid/36062Exploit
- http://www.ush.it/2009/08/18/vtiger-crm-504-multiple-vulnerabilities/Exploit
- http://www.ush.it/team/ush/hack-vtigercrm_504/vtigercrm_504.txtExploit
- http://www.vupen.com/english/advisories/2009/2319Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.