Dolibarr

Dolibarr

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 86.99%
  • Veröffentlicht 22.05.2018 20:29:01
  • Zuletzt bearbeitet 21.11.2024 03:40:48

Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.

Exploit
  • EPSS 70.93%
  • Veröffentlicht 22.05.2018 20:29:01
  • Zuletzt bearbeitet 21.11.2024 03:40:48

SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.

Exploit
  • EPSS 2.04%
  • Veröffentlicht 22.05.2018 20:29:01
  • Zuletzt bearbeitet 21.11.2024 03:40:48

The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.

  • EPSS 1.31%
  • Veröffentlicht 11.09.2017 09:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter.

  • EPSS 0.72%
  • Veröffentlicht 11.09.2017 09:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php.

  • EPSS 1.16%
  • Veröffentlicht 11.09.2017 09:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

There is a sensitive information disclosure vulnerability in document.php in Dolibarr ERP/CRM version 6.0.0 via the file parameter.

  • EPSS 0.72%
  • Veröffentlicht 11.09.2017 09:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7...

  • EPSS 1.31%
  • Veröffentlicht 11.09.2017 09:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter.

  • EPSS 1.46%
  • Veröffentlicht 25.06.2017 12:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application.

  • EPSS 1.48%
  • Veröffentlicht 05.06.2017 14:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Dolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters).