Laurent Destailleur
62 exploits
Active since Dec 2011
Dolibarr 6.0.0 - Authenticated Stored Cross-Site Scripting via Title Parameter
CVSS 5.4
Dolibarr 6.0.0 - SQL Injection via don/list.php statut Parameter
CVSS 9.8
Dolibarr ERP/CRM 6.0.4 - SQL Injection via comm/multiprix.php id Parameter
CVSS 9.8
Dolibarr ERP/CRM 6.0.4 - Exposure of Sensitive Information via Direct TPL.PHP File Access
CVSS 7.5
Dolibarr ERP/CRM 6.0.4 - SQL Injection via adherents/subscription/info.php rowid Parameter
CVSS 9.8
Dolibarr ERP/CRM < 6.0.5 - SQL Injection via fourn/index.php socid Parameter
CVSS 9.8
Dolibarr ERP/CRM <5.0.3 - SQL Injection
CVSS 9.8
Dolibarr <7.0.2 - Command Injection
CVSS 8.0
Dolibarr < 7.0.2 - Cross-Site Scripting via foruserlogin Parameter
CVSS 6.1
Dolibarr ERP/CRM 7.0.3 - SQL Injection via statut Parameter
CVSS 9.8
Dolibarr 7.0.3 - SQL Injection via country_id Parameter
CVSS 9.8
Dolibarr ERP/CRM 7.0.3 - SQL Injection via statut_buy Parameter
CVSS 9.8
Dolibarr 7.0.3 - SQL Injection via Status Batch Parameter
CVSS 9.8
Dolibarr < 8.0.4 - Authenticated Stored Cross-Site Scripting via Address or Town Parameter
CVSS 5.4
Dolibarr 8.0.2 - Reflected Cross-Site Scripting via transphrase Parameter
CVSS 6.1
Dolibarr 8.0.2 - Authenticated SQL Injection via desiredstock Parameter
CVSS 8.8
Dolibarr < 8.0.4 - Authenticated Stored Cross-Site Scripting via User Address or Town Parameter
CVSS 5.4
Dolibarr 8.0.2 - Authenticated SQL Injection via Employee Parameter
CVSS 8.8
Dolibarr < 7.0.2 - SQL Injection via sortfield Parameter
CVSS 9.8
Dolibarr < 11.0.4 - Authenticated Access Control Bypass via Non-Alphanumeric Menu Parameter
CVSS 8.8
Dolibarr < 11.0.3 and >=0 < 11.0.5 - Authenticated SQL Injection via id Parameter
CVSS 8.8
Dolibarr < 11.0.5 - Reflected Cross-Site Scripting in public/notice.php
CVSS 6.1
Dolibarr <12.0.3 - Authenticated RCE
CVSS 7.2
Dolibarr 2.8.1-13.0.4 - Improper Access Control in Private Note Endpoint
CVSS 4.3
Dolibarr 2.8.1-13.0.2 - Stored Cross-Site Scripting in Private Note Field
CVSS 9.0