Fixed in 6.0.5

2017-12-26 8:00 GMT+01:00 Salvatore Bonaccorso <[email protected]>:

> Source: dolibarr
> Version: 3.5.5+dfsg1-1
> Severity: important
> Tags: patch security upstream
>
> Hi,
>
> the following vulnerability was published for dolibarr.
>
> CVE-2017-14242[0]:
> | SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0
> | allows remote attackers to execute arbitrary SQL commands via the
> | statut parameter.
>
> The code in question was moved several times around e.g. from
> htdocs/compta/dons/list.php to htdocs/donations/list.php, then to the
> dons directory.
>
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
>
> For further information see:
>
> [0] https://security-tracker.debian.org/tracker/CVE-2017-14242
>     https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14242
>
> Please adjust the affected versions in the BTS as needed.
>
> Regards,
> Salvatore
>



-- 
EMail: [email protected]
Web: http://www.destailleur.fr
------------------------------------------------------------------------------------
Google+: https://plus.google.com/+LaurentDestailleur-Open-Source-Expert/
Facebook: https://www.facebook.com/Destailleur.Laurent
Twitter: http://www.twitter.com/eldy10
------------------------------------------------------------------------------------
* Dolibarr (Project leader): https://www.dolibarr.org (make a donation for
Dolibarr project via Paypal: [email protected])
* AWStats (Author) : http://awstats.sourceforge.net (make a donation for
AWStats project via Paypal: [email protected])
* AWBot (Author) : http://awbot.sourceforge.net
* CVSChangeLogBuilder (Author) : http://cvschangelogb.sourceforge.net

Reply via email to