Fixed in 6.0.5 2017-12-26 8:00 GMT+01:00 Salvatore Bonaccorso <[email protected]>:
> Source: dolibarr > Version: 3.5.5+dfsg1-1 > Severity: important > Tags: patch security upstream > > Hi, > > the following vulnerability was published for dolibarr. > > CVE-2017-14242[0]: > | SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 > | allows remote attackers to execute arbitrary SQL commands via the > | statut parameter. > > The code in question was moved several times around e.g. from > htdocs/compta/dons/list.php to htdocs/donations/list.php, then to the > dons directory. > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > For further information see: > > [0] https://security-tracker.debian.org/tracker/CVE-2017-14242 > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14242 > > Please adjust the affected versions in the BTS as needed. > > Regards, > Salvatore > -- EMail: [email protected] Web: http://www.destailleur.fr ------------------------------------------------------------------------------------ Google+: https://plus.google.com/+LaurentDestailleur-Open-Source-Expert/ Facebook: https://www.facebook.com/Destailleur.Laurent Twitter: http://www.twitter.com/eldy10 ------------------------------------------------------------------------------------ * Dolibarr (Project leader): https://www.dolibarr.org (make a donation for Dolibarr project via Paypal: [email protected]) * AWStats (Author) : http://awstats.sourceforge.net (make a donation for AWStats project via Paypal: [email protected]) * AWBot (Author) : http://awbot.sourceforge.net * CVSChangeLogBuilder (Author) : http://cvschangelogb.sourceforge.net

