Vulnerability title: Multiple SQL Injections in Dolibarr ERP & CRM
CVE: CVE-2014-7137
Vendor: Dolibarr ERP & CRM
Product: Dolibarr ERP & CRM
Affected version: 3.5.3
Fixed version: 3.6.1
Reported by: Jerzy Kramarz
Details:
SQL injection has been found and confirmed within the software as an authenticated user. A successful attack could allow an authenticated attacker to access information such as usernames and password hashes that are stored in the database.
The following URL and parameters have been confirmed to suffer from various forms of SQL injections:
http://[IP]/dolibarr/product/ stock/fiche.php?action=edit& id=1<SQL Injection>
http://[IP]/dolibarr/product/ stock/liste.php?sref=55<SQL Injection>&token= 142abe4c1c4b84c3d0c81533c3840c c4&sall=55
http://[IP]/dolibarr/product/ stock/liste.php?sref=555-555- 0199@example.com&token= 142abe4c1c4b84c3d0c81533c3840c c4&sall=55<SQL Injection>
http://[IP]/dolibarr/projet/ element.php?ref=PJ1407<SQL Injection>
http://[IP]/dolibarr/projet/ tasks/index.php?search_ project=5<SQL Injection>bqve&button_search. x=1&button_search.y=1&mode=
http://[IP]/dolibarr/compta/ prelevement/demandes.php? search_societe=5<SQL Injection>&search_facture=5& button_search.x=1&button_ search.y=1
http://[IP]/dolibarr/comm/ mailing/liste.php?sref=5<SQL Injection>&sall=5&x=1&y=1
http://[IP]/dolibarr/comm/ mailing/liste.php?sref=5&sall= 5<SQL Injection>&x=1&y=1
http://[IP]/dolibarr/compta/ sociales/index.php?search_ label=5<SQL Injection>&button_search.x=1& button_search.y=1
http://[IP]/dolibarr/compta/ paiement/cheque/liste.php? sortfield=bc.number<SQL Injection>&sortorder=asc& begin=&
http://[IP]/dolibarr/compta/ paiement/cheque/liste.php? sortfield=bc.number&sortorder= asc<SQL Injection>&begin=&
http://[IP]/dolibarr/compta/ prelevement/rejets.php? sortfield=p.ref<SQL Injection>&sortorder=asc& begin=&
http://[IP]/dolibarr/compta/ prelevement/rejets.php? sortfield=p.ref&sortorder=asc< SQL Injection>&begin=&
http://[IP]/dolibarr/product/ liste.php?sortfield=p.ref& sortorder=asc&begin=&sref=& snom=&sall=&tosell=<SQL Injection>&tobuy=&type=&
http://[IP]/dolibarr/product/ liste.php?sortfield=p.ref& sortorder=asc&begin=&sref=& snom=&sall=&tosell=&tobuy=<SQL Injection>&type=&
http://[IP]/dolibarr/product/ reassort.php?toolowstock=on& snom=5&sortorder=ASC&sref=5& token= d638ca7f80a7ad68e2cf327a75f954 a6&button_search.x=1&button_ search.y=1&type=&search_categ= 4<SQL Injection>&sortfield=stock_ physique
http://[IP]/dolibarr/product/ liste.php?sortfield=p.ref& sortorder=asc&begin=&sref=& snom=&sall=&tosell=1<SQL Injection>&tobuy=&type=&
http://[IP]/dolibarr/product/ liste.php?sortfield=p.ref& sortorder=asc&begin=&sref=& snom=&sall=&tosell=1&tobuy=< SQL Injection>&type=&
http://[IP]/dolibarr/product/ stats/commande_fournisseur. php?sortfield=c.rowid<SQL Injection>&sortorder=asc& begin=&id=2
http://[IP]/dolibarr/product/ stats/commande_fournisseur. php?sortfield=c.rowid& sortorder=asc<SQL Injection>&begin=&id=2
http://[IP]/dolibarr/product/ stats/contrat.php?sortfield=c. rowid<SQL Injection>&sortorder=asc& begin=&id=2
http://[IP]/dolibarr/product/ stats/contrat.php?sortfield=c. rowid'&sortorder=asc<SQL Injection>&begin=&id=2
http://[IP]/dolibarr/product/ stats/facture_fournisseur.php? sortfield=s.rowid<SQL Injection>&sortorder=asc& begin=&id=2
http://[IP]/dolibarr/product/ stats/facture_fournisseur.php? sortfield=s.rowid&sortorder= asc<SQL Injection>&begin=&id=2
http://[IP]/dolibarr/product/ stats/propal.php?sortfield=p. rowid<SQL Injection>&sortorder=asc& begin=&id=2
http://[IP]/dolibarr/product/ stats/propal.php?sortfield=p. rowid&sortorder=asc<SQL Injection>&begin=&id=2
http://[IP]/dolibarr/product/ stock/fiche.php?id=0<SQL Injection>
http://[IP]/dolibarr/product/ stock/info.php?id=0<SQL Injection>
http://[IP]/dolibarr/product/ stock/liste.phpsortfield=e. label&sortorder=asc<SQL Injection>&begin=&
http://[IP]/dolibarr/product/ stock/liste.php?sortfield=e. label<SQL Injection>&sortorder=asc& begin=&
http://[IP]/dolibarr/product/ reassort.php?toolowstock=on& snom=5&sortorder=ASC&sref=5< SQL Injection>&token= d638ca7f80a7ad68e2cf327a75f954 a6&button_search.x=1&button_ search.y=1&type=&search_categ= 4&sortfield=stock_physique
http://[IP]/dolibarr/product/ stock/massstockmove.php? productid=1<SQL Injection>&token= 9d491e55462571d39390bd136f4f50 da&id_tw=-1&action=addline& qty=5&id_sw=-1&addline=%D8%B1% D8%AA%D8%AE%D8%A7&search_ productid=5
http://[IP]/dolibarr/product/ stock/replenishorders.php? sortfield=cf.ref&sortorder= asc<SQL Injection>&begin=&
http://[IP]/dolibarr/product/ stock/replenishorders.php? sortfield=cf.ref<SQL Injection>&sortorder=asc& begin=&
http://[IP]/dolibarr/projet/ contact.php?id=1&action= deletecontact&lineid=21<SQL Injection>
http://[IP]/dolibarr/projet/ contact.php?id=1&action= swapstatut&ligne=21<SQL Injection>
http://[IP]/dolibarr/projet/ tasks/contact.php?id=1&action= swapstatut&ligne=21<SQL Injection>
http://[IP]/dolibarr/compta/ recap-compta.php?socid=1<SQL Injection>
http://[IP]/dolibarr/holiday/ index.php?mainmenu=holiday&id= 1<SQL Injection>
http://[IP]/dolibarr/projet/ tasks/contact.php?id=2&source= internal&token= acff06ed1720e3ec66a16918dcee2b fd&action=addcontact&type=181& contactid=2<SQL Injection>&withproject=1
http://[IP]/dolibarr/product/ stock/fiche.php?id=1<SQL Injection>
http://[IP]/dolibarr/projet/ contact.php?ref=PJ1407-0002< SQL Injection>
http://[IP]/dolibarr/projet/ ganttview.php?ref=PJ1407-0002< SQL Injection>
http://[IP]/dolibarr/product/ stock/fiche.php?id=1<SQL Injection>
http://[IP]/dolibarr/projet/ note.php?ref=PJ1407-0002<SQL Injection>
http://[IP]/dolibarr/projet/ tasks/contact.php?project_ref= PJ1407-0002<SQL Injection>&withproject=1
http://[IP]/dolibarr/projet/ tasks.php?ref=PJ1407-0002<SQL Injection>&mode=mine
http://[IP]/dolibarr/projet/ tasks/note.php?project_ref= PJ1407-0002<SQL Injection>&withproject=1
http://[IP]/dolibarr/contact/ info.php?id=2<SQL Injection>&optioncss=print
http://[IP]/dolibarr/societe/ commerciaux.php?socid= 117260852<SQL Injection>&optioncss=print
http://[IP]/dolibarr/compta/ dons/liste.php?statut=2<SQL Injection>
http://[IP]/dolibarr/societe/ rib.php?socid=1<SQL Injection>&optioncss=print
http://[IP]/dolibarr/ adherents/liste.php?leftmenu= members&statut=1<SQL Injection>&filter=outofdate& idmenu=9431&mainmenu=members
http://[IP]/dolibarr/product/ reassort.php?sortfield=p.ref& sortorder=asc&begin=&tosell= 43<SQL Injection>&tobuy=&type=0& fourn_id=&snom=&sref=&
http://[IP]/dolibarr/product/ reassort.php?sortfield=p.ref& sortorder=asc&begin=&tosell=& tobuy=3<SQL Injection>&type=0&fourn_id=& snom=&sref=&
http://[IP]/dolhttp://[IP]/ dolibarr/product/index.php? leftmenu=product&type=0<SQL Injection>&idmenu=2819& mainmenu=products
http://[IP]/dolibarr/product/ stats/facture.php?sortfield=s. rowid<SQL Injection>&sortorder=asc& begin=&id=2
http://[IP]/dolibarr/product/ stats/facture.php?sortfield=s. rowid&sortorder=asc<SQL Injection>&begin=&id=2
http://[IP]/dolibarr/user/ index.php?sortfield=u.login& sortorder=asc&begin=search_ user=&sall=&search_statut=<SQL Injection>&
http://[IP]/dolibarr/compta/ bank/fiche.php?id=<SQL Injection>
http://[IP]/dolibarr/compta/ prelevement/liste.php?search_ code=5<SQL Injection>&search_societe=5& search_ligne=5&search_bon=5& button_search.x=1&button_ search.y=1
http://[IP]/dolibarr/compta/ prelevement/liste.php?search_ code=5&search_societe=5<SQL Injection>&search_ligne=5& search_bon=5&button_search.x= 1&button_search.y=1
http://[IP]/dolibarr/compta/ prelevement/liste.php?search_ code=5&search_societe=5& search_ligne=5<SQL Injection>&search_bon=5& button_search.x=1&button_ search.y=1
http://[IP]/dolibarr/compta/ prelevement/liste.php?search_ code=5&search_societe=5& search_ligne=5&search_bon=5< SQL Injection>&button_search.x=1& button_search.y=1
http://[IP]/dolibarr/compta/ prelevement/bons.php? sortfield=p.ref&sortorder=asc< SQL Injection>&begin=&
http://[IP]/dolibarr/compta/ prelevement/bons.php? sortfield=p.ref<SQL Injection>&sortorder=asc& begin=&
http://[IP]/dolibarr/product/ stats/commande.php?sortfield= c.rowid&sortorder=asc<SQL Injection>&begin=&id=2
http://[IP]/dolibarr/product/ stats/commande.php?sortfield= c.rowid<SQL Injection>&sortorder=asc& begin=&id=2
Further details at:
https://www.portcullis- security.com/security- research-and-downloads/ security-advisories/cve-2014- 7137/
Copyright:
Copyright (c) Portcullis Computer Security Limited 2014, All rights reserved worldwide. Permission is hereby granted for the electronic redistribution of this information. It is not to be edited or altered in any way without the express written consent of Portcullis Computer Security Limited.
Disclaimer:
The information herein contained may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Portcullis Computer Security Limited) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
CVE: CVE-2014-7137
Vendor: Dolibarr ERP & CRM
Product: Dolibarr ERP & CRM
Affected version: 3.5.3
Fixed version: 3.6.1
Reported by: Jerzy Kramarz
Details:
SQL injection has been found and confirmed within the software as an authenticated user. A successful attack could allow an authenticated attacker to access information such as usernames and password hashes that are stored in the database.
The following URL and parameters have been confirmed to suffer from various forms of SQL injections:
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/comm/
http://[IP]/dolibarr/comm/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/holiday/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/projet/
http://[IP]/dolibarr/contact/
http://[IP]/dolibarr/societe/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/societe/
http://[IP]/dolibarr/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolhttp://[IP]/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/user/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/compta/
http://[IP]/dolibarr/product/
http://[IP]/dolibarr/product/
Further details at:
https://www.portcullis-
Copyright:
Copyright (c) Portcullis Computer Security Limited 2014, All rights reserved worldwide. Permission is hereby granted for the electronic redistribution of this information. It is not to be edited or altered in any way without the express written consent of Portcullis Computer Security Limited.
Disclaimer:
The information herein contained may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Portcullis Computer Security Limited) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.