CVE-2008-3458 Information
Feb 14, 2021
cve
Description
Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.
Reference
http://secunia.com/advisories/28370 http://sourceforge.net/project/shownotes.php?release_id=567189 http://trac.vtiger.com/cgi-bin/trac.cgi/changeset/11811 http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/2107 http://wiki.vtiger.com/index.php/Vtiger_CRM_5.0.4_-_Release_Notes http://www.osvdb.org/40218 http://www.securityfocus.com/bid/27228
Share on: