Index: vuln.xml =================================================================== RCS file: /home/pcvs/ports/security/vuxml/vuln.xml,v retrieving revision 1.1190 diff -u -r1.1190 vuln.xml --- vuln.xml 14 Oct 2006 12:32:43 -0000 1.1190 +++ vuln.xml 15 Oct 2006 01:48:10 -0000 @@ -34,6 +34,36 @@ --> + + vtiger -- multiple remote file inclusion vulnerability + + + vtiger + 5.0 + + + + +

Dedi Dwianto a.k.a the_day reports:

+
+

Input passed to the "$calpath" parameter in update.php is + not properly verified before being used. This can be + exploited to execute arbitrary PHP code by including files + from local or external resources.

+
+ +
+ + CVE-2006-5289 + 20435 + http://advisories.echo.or.id/adv/adv54-theday-2006.txt + + + 2006-10-09 + 2006-10-15 + +
+ google-earth -- heap overflow in the KML engine