Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.70685
Kategorie:Mandrake Local Security Checks
Titel:Mandriva Security Advisory MDVSA-2012:014 (glpi)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to glpi
announced via advisory MDVSA-2012:014.

A vulnerability has been found and corrected in GLPI:

The autocompletion functionality in GLPI before 0.80.2 does not
blacklist certain username and password fields, which allows remote
attackers to obtain sensitive information via a crafted POST request
(CVE-2011-2720).

This advisory provides the latest version of GLPI (0.80.6) which are
not vulnerable to this issue. Additionally the latest versions of
the corresponding plugins are also being provided.

Affected: Enterprise Server 5.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2012:014

Risk factor : High

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-2720
45366
http://secunia.com/advisories/45366
45542
http://secunia.com/advisories/45542
48884
http://www.securityfocus.com/bid/48884
FEDORA-2011-9639
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063408.html
FEDORA-2011-9690
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063679.html
MDVSA-2012:014
http://www.mandriva.com/security/advisories?name=MDVSA-2012:014
[oss-security] 20110725 CVE Request -- GLPI -- Properly blacklist some sensitive fields
http://www.openwall.com/lists/oss-security/2011/07/25/7
[oss-security] 20110726 Re: CVE Request -- GLPI -- Properly blacklist some sensitive fields
http://www.openwall.com/lists/oss-security/2011/07/26/11
http://www.glpi-project.org/spip.php?page=annonce&id_breve=237&lang=en
https://bugzilla.redhat.com/show_bug.cgi?id=726185
https://forge.indepnet.net/issues/3017
https://forge.indepnet.net/projects/glpi/repository/revisions/14951
https://forge.indepnet.net/projects/glpi/repository/revisions/14952
https://forge.indepnet.net/projects/glpi/repository/revisions/14954
https://forge.indepnet.net/projects/glpi/repository/revisions/14955
https://forge.indepnet.net/projects/glpi/repository/revisions/14956
https://forge.indepnet.net/projects/glpi/repository/revisions/14957
https://forge.indepnet.net/projects/glpi/repository/revisions/14958
https://forge.indepnet.net/projects/glpi/repository/revisions/14960
https://forge.indepnet.net/projects/glpi/repository/revisions/14966
https://forge.indepnet.net/projects/glpi/versions/605
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.