Vtiger CRM是美国Vtiger公司的一套基于SugarCRM开发的客户关系管理系统(CRM)。该管理系统提供管理、收集、分析客户信息等功能。 vTiger CRM 5.0.0至5.4.0版本中存在SQL注入漏洞,该漏洞源于soap/customerportal.php脚本没有正确过滤get_picklists方法中的‘picklist_name’参数;soap/customerportal.php脚本没有正确过滤get_tickets_list方法中的‘where’参数;soap/vtigerol
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-1311 | Apple Safari WebKit 缓冲区溢出漏洞 | |
| CVE-2014-2138 | Cisco Security Manager CRLF注入漏洞 | |
| CVE-2014-2137 | Cisco Web Security Appliance CRLF注入漏洞 | |
| CVE-2014-2125 | Cisco Unity Connection 跨站脚本漏洞 | |
| CVE-2014-1942 | Pearson eSIS Enterprise Student Information System 跨站脚本漏洞 | |
| CVE-2014-0901 | IBM WebSphere Portal 跨站脚本漏洞 | |
| CVE-2014-0828 | IBM WebSphere Portal Web Content Manager UI 跨站脚本漏洞 | |
| CVE-2013-3588 | Zyxel P660 拒绝服务漏洞 | |
| CVE-2014-2655 | Postfix Admin‘gen_show_status’函数SQL注入漏洞 | |
| CVE-2014-2578 | Splunk 跨站脚本漏洞 | |
| CVE-2014-2553 | Open Ticket Request System 跨站脚本漏洞 | |
| CVE-2013-5365 | Autodesk SketchBook 基于堆的缓冲区溢出漏洞 | |
| CVE-2013-4240 | WordPress HMS Testimonials 跨站请求伪造漏洞 | |
| CVE-2013-1770 | Ganglia Web ’view_name‘参数跨站脚本漏洞 | |
| CVE-2014-1313 | Apple Safari WebKit 缓冲区溢出漏洞 | |
| CVE-2014-1312 | Apple Safari WebKit 缓冲区溢出漏洞 | |
| CVE-2013-0735 | WordPress Mingle Forum插件SQL注入漏洞 | |
| CVE-2014-1310 | Apple Safari WebKit 缓冲区溢出漏洞 | |
| CVE-2014-1309 | Apple Safari WebKit 缓冲区溢出漏洞 | |
| CVE-2014-1308 | Apple Safari WebKit 缓冲区溢出漏洞 |
Showing top 20 of 33 CVEs. View all on vendor page → →
No comments yet