vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
vtiger CRM
Exploit
CVE-2013-3214
NVD
Refer to CVE-2013-3214 NVD advisory