Vulnerability Details CVE-2010-3909
Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by using the draft save feature in the Compose Mail component to upload a file with a .phtml extension, and then accessing this file via a direct request to the file in the storage/ directory tree.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.026
EPSS Ranking 85.1%
CVSS Severity
CVSS v2 Score 6.0
Products affected by CVE-2010-3909
-
cpe:2.3:a:vtiger:vtiger_crm:1.0
-
cpe:2.3:a:vtiger:vtiger_crm:2.0
-
cpe:2.3:a:vtiger:vtiger_crm:2.0.1
-
cpe:2.3:a:vtiger:vtiger_crm:2.1
-
cpe:2.3:a:vtiger:vtiger_crm:3
-
cpe:2.3:a:vtiger:vtiger_crm:3.0
-
cpe:2.3:a:vtiger:vtiger_crm:3.2
-
cpe:2.3:a:vtiger:vtiger_crm:4
-
cpe:2.3:a:vtiger:vtiger_crm:4.0
-
cpe:2.3:a:vtiger:vtiger_crm:4.0.1
-
cpe:2.3:a:vtiger:vtiger_crm:4.2
-
cpe:2.3:a:vtiger:vtiger_crm:4.2.4
-
cpe:2.3:a:vtiger:vtiger_crm:5
-
cpe:2.3:a:vtiger:vtiger_crm:5.0
-
cpe:2.3:a:vtiger:vtiger_crm:5.0.0
-
cpe:2.3:a:vtiger:vtiger_crm:5.0.1
-
cpe:2.3:a:vtiger:vtiger_crm:5.0.2
-
cpe:2.3:a:vtiger:vtiger_crm:5.0.3
-
cpe:2.3:a:vtiger:vtiger_crm:5.0.4
-
cpe:2.3:a:vtiger:vtiger_crm:5.1.0
-
cpe:2.3:a:vtiger:vtiger_crm:5.2.0
-
cpe:2.3:a:vtiger:vtiger_crm:5.2.1
-
cpe:2.3:a:vtiger:vtiger_crm:5.3.0
-
cpe:2.3:a:vtiger:vtiger_crm:5.4.0
-
cpe:2.3:a:vtiger:vtiger_crm:6.0
-
cpe:2.3:a:vtiger:vtiger_crm:6.0.0
-
cpe:2.3:a:vtiger:vtiger_crm:6.1.0
-
cpe:2.3:a:vtiger:vtiger_crm:6.2.0
-
cpe:2.3:a:vtiger:vtiger_crm:6.3.0
-
cpe:2.3:a:vtiger:vtiger_crm:6.4.0
-
cpe:2.3:a:vtiger:vtiger_crm:6.5.0
-
cpe:2.3:a:vtiger:vtiger_crm:7.0
-
cpe:2.3:a:vtiger:vtiger_crm:7.0.1
-
cpe:2.3:a:vtiger:vtiger_crm:7.1.0
-
cpe:2.3:a:vtiger:vtiger_crm:7.2.0
-
cpe:2.3:a:vtiger:vtiger_crm:7.3.0
-
cpe:2.3:a:vtiger:vtiger_crm:7.4.0
-
cpe:2.3:a:vtiger:vtiger_crm:7.5.0