CVE-2006-4588

vtiger CRM 4.2.4, and possibly earlier, allows remote attackers to bypass authentication and access administrative modules via a direct request to index.php with a modified module parameter, as demonstrated using the Settings module.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vtiger:vtiger_crm:4.2:*:*:*:*:*:*:*
cpe:2.3:a:vtiger:vtiger_crm:4.2.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-09-06 22:04

Updated : 2024-02-04 16:52


NVD link : CVE-2006-4588

Mitre link : CVE-2006-4588

CVE.ORG link : CVE-2006-4588


JSON object : View

Products Affected

vtiger

  • vtiger_crm