vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats | third party advisory exploit |
https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one | third party advisory |
http://www.securityfocus.com/bid/63454 | vdb entry third party advisory |
http://www.exploit-db.com/exploits/29319 | exploit vdb entry third party advisory |