Lucene search

K
cveMitreCVE-2012-1225
HistoryFeb 21, 2012 - 1:31 p.m.

CVE-2012-1225

2012-02-2113:31:47
CWE-89
mitre
web.nvd.nist.gov
31
2
cve-2012-1225
dolibarr cms
sql injection
remote code execution
security vulnerability
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.3

Confidence

Low

EPSS

0.001

Percentile

28.6%

Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) rowid parameter to adherents/fiche.php.

Affected configurations

Nvd
Node
dolibarrdolibarr_erp\/crmRange3.2.0alpha
OR
dolibarrdolibarr_erp\/crmMatch2.5.0
OR
dolibarrdolibarr_erp\/crmMatch2.6.0
OR
dolibarrdolibarr_erp\/crmMatch2.6.1
OR
dolibarrdolibarr_erp\/crmMatch2.7.0
OR
dolibarrdolibarr_erp\/crmMatch2.7.1
OR
dolibarrdolibarr_erp\/crmMatch2.8.0
OR
dolibarrdolibarr_erp\/crmMatch2.8.1
OR
dolibarrdolibarr_erp\/crmMatch2.9.0
OR
dolibarrdolibarr_erp\/crmMatch3.0.0
OR
dolibarrdolibarr_erp\/crmMatch3.0.1
OR
dolibarrdolibarr_erp\/crmMatch3.1.0
OR
dolibarrdolibarr_erp\/crmMatch3.1.0rc
VendorProductVersionCPE
dolibarrdolibarr_erp\/crm*cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:alpha:*:*:*:*:*:*
dolibarrdolibarr_erp\/crm2.5.0cpe:2.3:a:dolibarr:dolibarr_erp\/crm:2.5.0:*:*:*:*:*:*:*
dolibarrdolibarr_erp\/crm2.6.0cpe:2.3:a:dolibarr:dolibarr_erp\/crm:2.6.0:*:*:*:*:*:*:*
dolibarrdolibarr_erp\/crm2.6.1cpe:2.3:a:dolibarr:dolibarr_erp\/crm:2.6.1:*:*:*:*:*:*:*
dolibarrdolibarr_erp\/crm2.7.0cpe:2.3:a:dolibarr:dolibarr_erp\/crm:2.7.0:*:*:*:*:*:*:*
dolibarrdolibarr_erp\/crm2.7.1cpe:2.3:a:dolibarr:dolibarr_erp\/crm:2.7.1:*:*:*:*:*:*:*
dolibarrdolibarr_erp\/crm2.8.0cpe:2.3:a:dolibarr:dolibarr_erp\/crm:2.8.0:*:*:*:*:*:*:*
dolibarrdolibarr_erp\/crm2.8.1cpe:2.3:a:dolibarr:dolibarr_erp\/crm:2.8.1:*:*:*:*:*:*:*
dolibarrdolibarr_erp\/crm2.9.0cpe:2.3:a:dolibarr:dolibarr_erp\/crm:2.9.0:*:*:*:*:*:*:*
dolibarrdolibarr_erp\/crm3.0.0cpe:2.3:a:dolibarr:dolibarr_erp\/crm:3.0.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

Social References

More

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.3

Confidence

Low

EPSS

0.001

Percentile

28.6%