← All CVEs

CVE-2014-2268

medium · 5

views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.

5
CVSS
31.2%
EPSS (exploit prob.)
98th
EPSS percentile
2014-11-16
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
vtigervtiger_crm1.0
vtigervtiger_crm2.0
vtigervtiger_crm2.0.1
vtigervtiger_crm2.1
vtigervtiger_crm3.0
vtigervtiger_crm3.0
vtigervtiger_crm3.2
vtigervtiger_crm4
vtigervtiger_crm4
vtigervtiger_crm4
vtigervtiger_crm4.0
vtigervtiger_crm4.0.1
vtigervtiger_crm4.2
vtigervtiger_crm4.2.4
vtigervtiger_crm5.0.0
vtigervtiger_crm5.0.1
vtigervtiger_crm5.0.2
vtigervtiger_crm5.0.3
vtigervtiger_crm5.0.4
vtigervtiger_crm5.0.4
vtigervtiger_crm5.1.0
vtigervtiger_crm5.1.0
vtigervtiger_crm5.2.0
vtigervtiger_crm5.2.1
vtigervtiger_crm5.3.0
vtigervtiger_crm5.4.0
vtigervtiger_crm6.0.0
vtigervtiger_crm6.0.0
vtigervtiger_crm6.0.0
vtigervtiger_crm6.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-2268