Description
SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin EZPZ One Click Backup 'mail' Parameter Cross-Site Scripting (12.03.10)
WordPress Plugin ZoomSounds-WordPress Wave Audio Player with Playlist Arbitrary File Upload (2.0)
PHP Use of Uninitialized Resource Vulnerability (CVE-2015-8390)
WordPress Plugin WP SlackSync Information Disclosure (1.8.5)