CVE-2011-4802
Summary
| CVE | CVE-2011-4802 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-12-14 00:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple SQL injection vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) sortfield, (2) sortorder, and (3) sall parameters to user/index.php and (b) user/group/index.php; the id parameter to (4) info.php, (5) perms.php, (6) param_ihm.php, (7) note.php, and (8) fiche.php in user/; and (9) rowid parameter to admin/boxes.php. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dolibarr | Dolibarr Erp/crm | 2.5.0 | All | All | All |
| Application | Dolibarr | Dolibarr Erp/crm | 2.6.0 | All | All | All |
| Application | Dolibarr | Dolibarr Erp/crm | 2.6.1 | All | All | All |
| Application | Dolibarr | Dolibarr Erp/crm | 2.7.0 | All | All | All |
| Application | Dolibarr | Dolibarr Erp/crm | 2.7.1 | All | All | All |
| Application | Dolibarr | Dolibarr Erp/crm | 2.8.0 | All | All | All |
| Application | Dolibarr | Dolibarr Erp/crm | 2.8.1 | All | All | All |
| Application | Dolibarr | Dolibarr Erp/crm | 2.9.0 | All | All | All |
| Application | Dolibarr | Dolibarr Erp/crm | 3.0.0 | All | All | All |
| Application | Dolibarr | Dolibarr Erp/crm | 3.0.1 | All | All | All |
| Application | Dolibarr | Dolibarr Erp/crm | All | rc | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/77342 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| osvdb.org/77343 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| osvdb.org/77340 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| osvdb.org/77341 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| osvdb.org/77347 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link, Exploit |
| osvdb.org/77346 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link, Exploit |
| osvdb.org/77345 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| osvdb.org/77344 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| Fix: [Bug #232] Multiple Cross-Site-Scripting vulnerabilities · Dolibarr/dolibarr@762f98a · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| Security: A lot of security fixes · Dolibarr/dolibarr@63820ab · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| Security: More security holes fixed · Dolibarr/dolibarr@c539155 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| Fix: Sanitize PHP_SELF · Dolibarr/dolibarr@d08d28c · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Patch |
| Dolibarr Multiple Cross Site Scripting and SQL Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Third Party Advisory, VDB Entry |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| File Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.htbridge.ch | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.