RULE(RULE ID:323877)

Rule General Information
Release Date: 2019-11-29
Rule Name: Dolibarr Gather Credentials via SQL Injection Vulnerability (CVE-2018-10094)
Severity:
CVE ID:
Rule Protection Details
Description: SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:44805
http://www.openwall.com/lists/oss-security/2018/05/21/1
https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog
https://github.com/Dolibarr/dolibarr/commit/7ade4e37f24d6859987bb9f6232f604325633fdd
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog