Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-9258
Description:SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter.
Test IDs: 1.3.6.1.4.1.25623.1.0.868665   1.3.6.1.4.1.25623.1.0.869187   1.3.6.1.4.1.25623.1.0.868692   1.3.6.1.4.1.25623.1.0.868877   1.3.6.1.4.1.25623.1.0.869196  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-9258
http://www.exploit-db.com/exploits/35528
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147296.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147313.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147271.html
http://www.mandriva.com/security/advisories?name=MDVSA-2015:167
http://security.szurek.pl/glpi-085-blind-sql-injection.html
http://osvdb.org/show/osvdb/115957
http://secunia.com/advisories/61367




© 1998-2025 E-Soft Inc. All rights reserved.