CVE

Id
15027  
CVE No.
CVE-2005-3823  
Status
Candidate  
Description
The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parameter, which is passed to the eval function.  
Phase
Assigned (20051126)  
Votes
None (candidate not yet proposed)  
Comments