7.5
CVSSv2

CVE-2012-1226

Published: 21/02/2012 Updated: 17/11/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote malicious users to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the (1) file parameter to document.php or (2) backtopage parameter in a create action to comm/action/fiche.php.

Vulnerable Product Search on Vulmon Subscribe to Product

dolibarr dolibarr erp\\/crm 3.2.0

Exploits

Title: ====== Dolibarr CMS v320 Alpha - File Include Vulnerabilities Date: ===== 2012-02-07 References: =========== wwwvulnerability-labcom/get_contentphp?id=428 VL-ID: ===== 428 Introduction: ============= Dolibarr ERP & CRM is a modern software to manage your company or foundation activity (contacts, suppliers, invoices, ...
source: wwwsecurityfocuscom/bid/52113/info Dolibarr is prone to multiple directory-traversal vulnerabilities because it fails to sufficiently sanitize user-supplied input Exploiting the issues can allow an attacker to obtain sensitive information that could aid in further attacks Dolibarr 320 Alpha is vulnerable; other versions may ...