![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2005-3822 |
Description: | Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username in the login form or (2) record parameter, as demonstrated in the EditView action for the Contacts module. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2005-3822 BugTraq ID: 15569 http://www.securityfocus.com/bid/15569 Bugtraq: 20051125 SEC Consult SA-20051125-0 :: More Vulnerabilities in vTiger CRM (Google Search) http://www.securityfocus.com/archive/1/417711/30/0/threaded http://marc.info/?l=full-disclosure&m=113290708121951&w=2 http://securitytracker.com/id?1015274 http://secunia.com/advisories/17693 http://securityreason.com/securityalert/203 http://www.vupen.com/english/advisories/2005/2569 |