Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.831540
Kategorie:Mandrake Local Security Checks
Titel:Mandriva Update for glpi MDVSA-2012:014 (glpi)
Zusammenfassung:The remote host is missing an update for the 'glpi'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'glpi'
package(s) announced via the referenced advisory.

Vulnerability Insight:
A vulnerability has been found and corrected in GLPI:

The autocompletion functionality in GLPI before 0.80.2 does not
blacklist certain username and password fields, which allows remote
attackers to obtain sensitive information via a crafted POST request
(CVE-2011-2720).

This advisory provides the latest version of GLPI (0.80.6) which are
not vulnerable to this issue. Additionally the latest versions of
the corresponding plugins are also being provided.

Affected Software/OS:
glpi on Mandriva Enterprise Server 5,
Mandriva Enterprise Server 5/X86_64

Solution:
Please Install the Updated Packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-2720
45366
http://secunia.com/advisories/45366
45542
http://secunia.com/advisories/45542
48884
http://www.securityfocus.com/bid/48884
FEDORA-2011-9639
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063408.html
FEDORA-2011-9690
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063679.html
MDVSA-2012:014
http://www.mandriva.com/security/advisories?name=MDVSA-2012:014
[oss-security] 20110725 CVE Request -- GLPI -- Properly blacklist some sensitive fields
http://www.openwall.com/lists/oss-security/2011/07/25/7
[oss-security] 20110726 Re: CVE Request -- GLPI -- Properly blacklist some sensitive fields
http://www.openwall.com/lists/oss-security/2011/07/26/11
http://www.glpi-project.org/spip.php?page=annonce&id_breve=237&lang=en
https://bugzilla.redhat.com/show_bug.cgi?id=726185
https://forge.indepnet.net/issues/3017
https://forge.indepnet.net/projects/glpi/repository/revisions/14951
https://forge.indepnet.net/projects/glpi/repository/revisions/14952
https://forge.indepnet.net/projects/glpi/repository/revisions/14954
https://forge.indepnet.net/projects/glpi/repository/revisions/14955
https://forge.indepnet.net/projects/glpi/repository/revisions/14956
https://forge.indepnet.net/projects/glpi/repository/revisions/14957
https://forge.indepnet.net/projects/glpi/repository/revisions/14958
https://forge.indepnet.net/projects/glpi/repository/revisions/14960
https://forge.indepnet.net/projects/glpi/repository/revisions/14966
https://forge.indepnet.net/projects/glpi/versions/605
CopyrightCopyright (C) 2012 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.