Description
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:06:00.316Z
Reserved: 2014-03-04T00:00:00.000Z
Link: CVE-2014-2268
No data.
Status : Modified
Published: 2014-11-16T01:59:00.130
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-2268
No data.
OpenCVE Enrichment
No data.
Weaknesses