Description
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
Remediation
References
Related Vulnerabilities
WordPress Plugin Simply Static Arbitrary File Download (1.6.2)
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.39)
WordPress Plugin EU Cookie Law for GDPR/CCPA Cross-Site Scripting (3.0.6)
MySQL CVE-2012-0118 Vulnerability (CVE-2012-0118)
WordPress Cryptographic Issues Vulnerability (CVE-2014-9037)