CVE Database
/

CVE-2005-3818

Back to search

CVE-2005-3818

Published: Nov 26, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) various input fields, including the contact, lead, and first or last name fields, (2) the record parameter in a DetailView action in the Leads module for index.php, (3) the $_SERVER['PHP_SELF'] variable, which is used in multiple locations such as index.php, and (4) aggregated RSS feeds in the RSS aggregation module.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2005-2569
vdb-entry
x_refsource_VUPEN
15562
vdb-entry
x_refsource_BID
1015271
vdb-entry
x_refsource_SECTRACK
21228
vdb-entry
x_refsource_OSVDB
vtiger-rss-xss(23363)
vdb-entry
x_refsource_XF
21227
vdb-entry
x_refsource_OSVDB
17693
third-party-advisory
x_refsource_SECUNIA
21230
vdb-entry
x_refsource_OSVDB
21229
vdb-entry
x_refsource_OSVDB
vtiger-multiple-fields-xss(23362)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now