Description
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
Remediation
References
Related Vulnerabilities
WordPress Plugin Slider Revolution Responsive Arbitrary File Upload (3.0.95)
phpMyAdmin Resource Management Errors Vulnerability (CVE-2014-9218)
MyBB Server-Side Request Forgery (SSRF) Vulnerability (CVE-2017-7566)
MySQL Other Vulnerability (CVE-2000-0148)
WordPress Plugin Quick Page/Post Redirect Security Bypass (5.1.9)