6.8

CVE-2010-3910

Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM before 5.2.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the lang_crm parameter to phprint.php or (2) the current_language parameter in an Accounts Import action to graph.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VtigerVtiger Crm Version <= 5.2.0
VtigerVtiger Crm Version1.0
VtigerVtiger Crm Version2.0
VtigerVtiger Crm Version2.0.1
VtigerVtiger Crm Version2.1
VtigerVtiger Crm Version3
VtigerVtiger Crm Version3.0
VtigerVtiger Crm Version3.0 Updatebeta
VtigerVtiger Crm Version3.2
VtigerVtiger Crm Version4
VtigerVtiger Crm Version4 Updatebeta
VtigerVtiger Crm Version4 Updaterc1
VtigerVtiger Crm Version4.0
VtigerVtiger Crm Version4.0.1
VtigerVtiger Crm Version4.2
VtigerVtiger Crm Version4.2 Editionvalidation
VtigerVtiger Crm Version4.2.4
VtigerVtiger Crm Version5.0.0
VtigerVtiger Crm Version5.0.2
VtigerVtiger Crm Version5.0.3
VtigerVtiger Crm Version5.0.4
VtigerVtiger Crm Version5.0.4 Updaterc
VtigerVtiger Crm Version5.1.0
VtigerVtiger Crm Version5.1.0 Updaterc
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.49% 0.802
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.