CVE-2013-2091: SQL Injection
Published Nov 20, 2019
·Updated
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
Affected Software
2 affected components
debian/dolibarr
dolibarr Dolibarr Erp\/crm=3.3.1
Event History
Nov 20, 2019
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2013-2091?
The severity of CVE-2013-2091 is critical with a CVSS score of 9.8.
2
How does the SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 work?
The SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands by exploiting the 'pays' parameter in fiche.php.
3
Which versions of Dolibarr ERP/CRM are affected by CVE-2013-2091?
Dolibarr ERP/CRM version 3.3.1 is affected by CVE-2013-2091.
4
Are there any remedies available for CVE-2013-2091?
There are no specific remedies available for CVE-2013-2091.
5
Where can I find more information about CVE-2013-2091?
You can find more information about CVE-2013-2091 on the Debian Security Tracker, Openwall mailing list, and IBM X-Force Exchange.