VYPR
Unrated severityNVD Advisory· Published Nov 16, 2014· Updated May 6, 2026

CVE-2014-2268

CVE-2014-2268

Description

views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.

Affected products

30
  • Vtiger/Vtiger CRM30 versions
    cpe:2.3:a:vtiger:vtiger_crm:3.2:*:*:*:*:*:*:*+ 29 more
    • cpe:2.3:a:vtiger:vtiger_crm:3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:4:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:4:beta:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:4:rc1:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:3.0:beta:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:4.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.0.4:rc:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.1.0:rc:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:5.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:6.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:6.0.0:beta:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:6.0.0:rc:*:*:*:*:*:*
    • cpe:2.3:a:vtiger:vtiger_crm:6.0.0:sp1:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.