6.8
CVSSv2

CVE-2013-5696

Published: 23/09/2013 Updated: 23/09/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

inc/central.class.php in GLPI prior to 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote malicious users to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action.

Vulnerable Product Search on Vulmon Subscribe to Product

glpi-project glpi 0.83.8

glpi-project glpi 0.83.9

glpi-project glpi 0.83.91

glpi-project glpi 0.84

glpi-project glpi 0.80.4

glpi-project glpi 0.80.3

glpi-project glpi 0.80.2

glpi-project glpi 0.80.1

glpi-project glpi 0.72

glpi-project glpi 0.71.6

glpi-project glpi 0.71.5

glpi-project glpi 0.70

glpi-project glpi 0.68.3

glpi-project glpi 0.68.2

glpi-project glpi 0.51

glpi-project glpi 0.5

glpi-project glpi 0.83.31

glpi-project glpi 0.83.3

glpi-project glpi 0.83.2

glpi-project glpi 0.83.1

glpi-project glpi 0.83

glpi-project glpi 0.78.2

glpi-project glpi 0.78.1

glpi-project glpi 0.78

glpi-project glpi 0.72.4

glpi-project glpi 0.71.1

glpi-project glpi 0.71

glpi-project glpi 0.68

glpi-project glpi 0.65

glpi-project glpi 0.6

glpi-project glpi 0.30

glpi-project glpi 0.21

glpi-project glpi 0.20

glpi-project glpi 0.83.6

glpi-project glpi 0.83.4

glpi-project glpi 0.80.61

glpi-project glpi 0.80.5

glpi-project glpi 0.80

glpi-project glpi 0.78.4

glpi-project glpi 0.72.2

glpi-project glpi 0.71.3

glpi-project glpi 0.70.2

glpi-project glpi 0.51a

glpi-project glpi 0.42

glpi-project glpi 0.40

glpi-project glpi 0.83.7

glpi-project glpi

glpi-project glpi 0.83.5

glpi-project glpi 0.80.7

glpi-project glpi 0.80.6

glpi-project glpi 0.78.5

glpi-project glpi 0.78.3

glpi-project glpi 0.72.3

glpi-project glpi 0.72.1

glpi-project glpi 0.71.4

glpi-project glpi 0.71.2

glpi-project glpi 0.70.1

glpi-project glpi 0.68.1

glpi-project glpi 0.41

glpi-project glpi 0.31

Vendor Advisories

Debian Bug report logs - #723837 glpi: Multiple security vulnerabilities Package: glpi; Maintainer for glpi is Pierre Chifflier <pollux@debianorg>; Source for glpi is src:glpi (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Fri, 20 Sep 2013 09:45:01 UTC Severity: important Tags: fixed-upstream, ...

Exploits

GLPI version 0841 suffers from improper access control bypass and PHP code injection vulnerabilities ...
## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # web site for more information on licensing and terms of use # metasploitcom/ ## require 'msf/core' class Metasploit3 < Msf::Exploit::Remote Rank = ManualRanking # Application database c ...
Advisory ID: HTB23173 Product: GLPI Vendor: INDEPNET Vulnerable Version(s): 0841 and probably prior Tested Version: 0841 Advisory Publication: September 11, 2013 [without technical details] Vendor Notification: September 11, 2013 Vendor Patch: September 12, 2013 Public Disclosure: October 2, 2013 Vulnerability Type: Improper Access Control [CWE ...