ECHO_ADV_54$2006 ----------------------------------------------------------------------------------------------- [ECHO_ADV_54$2006]vtiger CRM <=4.2 (calpath) Multiple Remote File Inclusion Vulnerability ----------------------------------------------------------------------------------------------- Author : Dedi Dwianto a.k.a the_day Date Found : October, 09th 2006 Location : Indonesia, Jakarta web : http://advisories.echo.or.id/adv/adv54-theday-2006.txt Critical Lvl : Highly critical Impact : System access Where : From Remote --------------------------------------------------------------------------- Affected software description: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Application : Vtiger CRM version : <=4.2 URL : http://vtiger.com vtiger CRM is 100% Open Source Customer Relationship Management solution built over LAMP/WAMP stack and other third-party open source packages. vtiger CRM software can be installed in Windows NT/2000/XP/2003 and different types Unix/Linux-based distributions, such as RedHat 7.2/8.0/9.0, Debian 3.0, SuSe 9.0, Fedora Core 3.0, Mandrake 10.0, Mac OS, and FreeBSD. --------------------------------------------------------------------------- Vulnerability: ~~~~~~~~~~~~~~ In folder modules/Calendar/admin/ I found vulnerability script update.php --------------------------update.php--------------------------------------- ....