7.5
CVSSv2

CVE-2013-2226

Published: 14/05/2014 Updated: 15/05/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in GLPI prior to 0.83.9 allow remote malicious users to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to ajax/comments.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

glpi-project glpi

glpi-project glpi 0.83.7

glpi-project glpi 0.83.6

glpi-project glpi 0.83.5

glpi-project glpi 0.83.1

glpi-project glpi 0.83

glpi-project glpi 0.83.4

glpi-project glpi 0.83.3

glpi-project glpi 0.83.31

glpi-project glpi 0.83.2

Vendor Advisories

Debian Bug report logs - #714720 glpi: Multiple security issues Package: glpi; Maintainer for glpi is Pierre Chifflier <pollux@debianorg>; Source for glpi is src:glpi (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 2 Jul 2013 06:45:01 UTC Severity: important Fixed in version glp ...

Exploits

GLPI v0838 Multiple Error-based SQL Injection Vulnerabilities Vendor: INDEPNET Development Team Product web page: wwwglpi-projectorg Affected version: 0837 and 0838 Summary: GLPI, an initialism for Gestionnaire libre de parc informatique (Free Management of Computer Equipment), was designed by Indepnet Association (a non profit o ...