Dolibarr 漏洞列表
共找到 13 个与 Dolibarr 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2012-1226: Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities POC
Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the (1) file parameter to document.php or (2) backtopage parameter in a create action to comm/action/fiche.php. -
CVE-2018-10095: Dolibarr <7.0.2 - Cross-Site Scripting POC
Dolibarr before 7.0.2 is vulnerable to cross-site scripting and allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php. -
CVE-2023-33568: Dolibarr Unauthenticated Contacts Database Theft POC
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists. -
CVE-2024-5315: Dolibarr ERP CMS `list.php` - SQL Injection POC
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. -
CVE-2012-1226: Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities POC
Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the (1) file parameter to document.php or (2) backtopage parameter in a create action to comm/action/fiche.php. -
CVE-2018-10095: Dolibarr <7.0.2 - Cross-Site Scripting POC
Dolibarr before 7.0.2 is vulnerable to cross-site scripting and allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php. -
CVE-2023-33568: Dolibarr Unauthenticated Contacts Database Theft POC
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists. -
CVE-2024-5315: Dolibarr ERP CMS `list.php` - SQL Injection POC
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. -
Dolibarr ERP CRM export.php 命令注入漏洞 无POC
Dolibarr ERP CRM存在命令注入漏洞,该漏洞是由于export.php对用户的请求缺乏验证。 -
Dolibarr ERP和CRM套件菜单编辑器dol_eval函数代码注入漏洞 无POC
Dolibarr ERP、CRM包中存在代码注入漏洞。该漏洞是由于 Menu editor 模块中 dol_eval 函数对用户的输入数据验证不足导致的。 -
Dolibarr CVE-2022-0224 SQL注入漏洞 无POC
-
Dolibarr存在信息泄漏漏洞(CVE-2023-33568) 无POC
Dolibarr是一个erp与crm软件,在漏洞收录时在GitHub平台有4.1k+star,在版本 <= 16.0.5存在信息泄漏漏洞。 -
Dolibarr edit.php 远程命令执行漏洞 (CVE-2022-40871) 无POC
Dolibarr edit.php 存在远程命令执行漏洞,攻击者通过逻辑漏洞创建管理员后可以通过后台漏洞获取服务器权限