CVE-2005-3819

vtiger CRM < 4.2 - SQL Injection via HelpDesk user_name and date Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-3819. PoCs published by Christopher Kunz.

AI-analyzed exploit summary The provided text describes multiple input validation vulnerabilities in vtiger CRM, including SQL injection, HTML injection, XSS, and local file inclusion. It includes a sample SQL injection payload but lacks executable exploit code.

Description

Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authentication via the (1) user_name and (2) date parameter in the HelpDesk module.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Christopher Kunz · textwebappsphp
https://www.exploit-db.com/exploits/26586

The provided text describes multiple input validation vulnerabilities in vtiger CRM, including SQL injection, HTML injection, XSS, and local file inclusion. It includes a sample SQL injection payload but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli | Xss | Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: vtiger CRM (version not specified)
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2569
Exploit, Vendor Advisory x_refsource_misc
http://www.hardened-php.net/advisory_232005.105.html
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15562
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015271
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/417730/30/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17693
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21225

Scores

EPSS 0.0284
EPSS Percentile 84.8%

Details

Status published
Products (1)
vtiger/vtiger_crm < 4.2
Published Nov 26, 2005
Tracked Since Feb 18, 2026