PT-2012-3149 · Dolibarr · Dolibarr Cms
Benjamin Kunz Mejri
+2
·
Publicado
2012-02-21
·
Atualizado
2022-11-17
·
CVE-2012-1226
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Dolibarr CMS version 3.2.0 Alpha
Description
The issue allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the
file parameter to "document.php" or backtopage parameter in a create action to "comm/action/fiche.php".Recommendations
For Dolibarr CMS version 3.2.0 Alpha, consider restricting access to the "document.php" and "comm/action/fiche.php" files until a patch is available. As a temporary workaround, avoid using the
file and backtopage parameters in the affected API endpoints until the issue is resolved.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dolibarr Cms