Логотип exploitDog
bind:CVE-2010-3909
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2010-3909

Количество 2

Количество 2

nvd логотип

CVE-2010-3909

около 15 лет назад

Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by using the draft save feature in the Compose Mail component to upload a file with a .phtml extension, and then accessing this file via a direct request to the file in the storage/ directory tree.

CVSS2: 6
EPSS: Низкий
github логотип

GHSA-8wgg-7fpq-c3vx

больше 3 лет назад

Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by using the draft save feature in the Compose Mail component to upload a file with a .phtml extension, and then accessing this file via a direct request to the file in the storage/ directory tree.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-3909

Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by using the draft save feature in the Compose Mail component to upload a file with a .phtml extension, and then accessing this file via a direct request to the file in the storage/ directory tree.

CVSS2: 6
3%
Низкий
около 15 лет назад
github логотип
GHSA-8wgg-7fpq-c3vx

Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by using the draft save feature in the Compose Mail component to upload a file with a .phtml extension, and then accessing this file via a direct request to the file in the storage/ directory tree.

3%
Низкий
больше 3 лет назад

Уязвимостей на страницу