Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

91 – 100 of 121 results


CVE-2018-10094

Medium priority
Vulnerable

SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2018-10092

Medium priority
Vulnerable

The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-9839

Medium priority
Vulnerable

Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter).

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-9838

Medium priority
Vulnerable

Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/card.php (type parameter),...

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-18260

Medium priority
Vulnerable

Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.php (viewstatut parameter) or comm/propal/list.php (propal_statut parameter, aka search_statut parameter).

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-18259

Medium priority
Vulnerable

Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-1000509

Medium priority
Vulnerable

Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-17971

Medium priority
Vulnerable

The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-17900

Medium priority
Vulnerable

SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2017-17899

Medium priority
Vulnerable

SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages