HTTP: Dolibarr ERP & CRM 3 Post Authentication Command Injection
This signature detects attempts to exploit a known vulnerability against Dolibarr ERP. A successful exploit can lead to remote command execution.
Extended Description
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
Affected Products
Dolibarr dolibarr_erp/crm
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Dolibarr
7.5