7.5
CVSSv2

CVE-2012-1225

Published: 21/02/2012 Updated: 17/11/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and previous versions allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) rowid parameter to adherents/fiche.php.

Vulnerable Product Search on Vulmon Subscribe to Product

dolibarr dolibarr erp\\/crm 2.9.0

dolibarr dolibarr erp\\/crm 2.8.1

dolibarr dolibarr erp\\/crm 2.6.0

dolibarr dolibarr erp\\/crm 3.0.0

dolibarr dolibarr erp\\/crm 2.7.1

dolibarr dolibarr erp\\/crm 2.6.1

dolibarr dolibarr erp\\/crm

dolibarr dolibarr erp\\/crm 2.5.0

dolibarr dolibarr erp\\/crm 3.1.0

dolibarr dolibarr erp\\/crm 2.8.0

dolibarr dolibarr erp\\/crm 2.7.0

dolibarr dolibarr erp\\/crm 3.0.1

Exploits

source: wwwsecurityfocuscom/bid/51956/info Dolibarr is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlyin ...