[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2012:014 -- Mandriva glpi

ID: oval:org.secpod.oval:def:1300023Date: (C)2013-04-08   (M)2022-10-10
Class: PATCHFamily: unix




A vulnerability has been found and corrected in GLPI: The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request . This advisory provides the latest version of GLPI which are not vulnerable to this issue. Additionally the latest versions of the corresponding plugins are also being provided.

Platform:
Mandriva Enterprise Server 5.2
Product:
glpi
Reference:
MDVSA-2012:014
CVE-2011-2720
CVE    1
CVE-2011-2720
CPE    1
cpe:/o:mandriva:enterprise_server:5.2

© SecPod Technologies