CVE-2011-4559
vtiger CRM < 5.2.1 - SQL Injection via Calendar Module onlyforuser Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-4559. PoCs published by Aung Khant.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in vtiger CRM 5.2.1 via the 'onlyforuser' parameter. The PoC includes crafted URLs that manipulate SQL queries to extract database version information or bypass authentication.
Description
SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in vtiger CRM 5.2.1 via the 'onlyforuser' parameter. The PoC includes crafted URLs that manipulate SQL queries to extract database version information or bypass authentication.