Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.70731
Categoría:FreeBSD Local Security Checks
Título:FreeBSD Ports: glpi
Resumen:The remote host is missing an update to the system; as announced in the referenced advisory.
Descripción:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: glpi

CVE-2011-2720
The autocompletion functionality in GLPI before 0.80.2 does not
blacklist certain username and password fields, which allows remote
attackers to obtain sensitive information via a crafted POST request.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-2720
45366
http://secunia.com/advisories/45366
45542
http://secunia.com/advisories/45542
48884
http://www.securityfocus.com/bid/48884
FEDORA-2011-9639
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063408.html
FEDORA-2011-9690
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063679.html
MDVSA-2012:014
http://www.mandriva.com/security/advisories?name=MDVSA-2012:014
[oss-security] 20110725 CVE Request -- GLPI -- Properly blacklist some sensitive fields
http://www.openwall.com/lists/oss-security/2011/07/25/7
[oss-security] 20110726 Re: CVE Request -- GLPI -- Properly blacklist some sensitive fields
http://www.openwall.com/lists/oss-security/2011/07/26/11
http://www.glpi-project.org/spip.php?page=annonce&id_breve=237&lang=en
https://bugzilla.redhat.com/show_bug.cgi?id=726185
https://forge.indepnet.net/issues/3017
https://forge.indepnet.net/projects/glpi/repository/revisions/14951
https://forge.indepnet.net/projects/glpi/repository/revisions/14952
https://forge.indepnet.net/projects/glpi/repository/revisions/14954
https://forge.indepnet.net/projects/glpi/repository/revisions/14955
https://forge.indepnet.net/projects/glpi/repository/revisions/14956
https://forge.indepnet.net/projects/glpi/repository/revisions/14957
https://forge.indepnet.net/projects/glpi/repository/revisions/14958
https://forge.indepnet.net/projects/glpi/repository/revisions/14960
https://forge.indepnet.net/projects/glpi/repository/revisions/14966
https://forge.indepnet.net/projects/glpi/versions/605
CopyrightCopyright (C) 2012 E-Soft Inc.

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.