Vtiger CRM Multiple Vulnerabilities April-14

Summary
This host is installed with Vtiger CRM and is prone to multiple vulnerabilities
Impact
Successful exploitation will allow remote attackers to change the password of any user or remote attackers can execute arbitrary php code. Impact Level: System/Application
Solution
Apply Security Patch 2 for Vtiger 6.0 (issued on March 16, 2014), For patch refer to, http://sourceforge.net/projects/vtigercrm/files/vtiger%20CRM%206.0.0/Add-ons
Insight
- No access control or restriction is enforced when the changePassword() function in 'forgotPassword.php' script is called. - Flaw in the install module that is triggered as input passed via the 'db_name' parameter is not properly sanitized.
Affected
Vtiger CRM version 6.0.0 (including Security Patch1), 6.0 RC, 6.0 Beta.
Detection
Send a crafted HTTP GET request and check whether it responds with error message.
References