4.3
CVSSv2

CVE-2005-3818

Published: 26/11/2005 Updated: 19/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and previous versions allow remote malicious users to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module.

Vulnerable Product Search on Vulmon Subscribe to Product

vtiger vtiger crm

Exploits

source: wwwsecurityfocuscom/bid/15562/info vtiger CRM is prone to multiple input validation vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input vTiger CRM is prone to multiple SQL injection, HTML injection, cross-site scripting and local file include vulnerabilities An atta ...
source: wwwsecurityfocuscom/bid/15562/info vtiger CRM is prone to multiple input validation vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input vTiger CRM is prone to multiple SQL injection, HTML injection, cross-site scripting and local file include vulnerabilities An attacke ...