6
CVSSv2

CVE-2016-7508

Published: 21/06/2017 Updated: 12/08/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote malicious user to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

glpi-project glpi 0.90.4

Exploits

# Exploit Title: Multiple SQL injection vulnerabilities in GLPI 0904 # Date: 2016/09/09 # Exploit Author: Eric CARTER (in/ericcarterengineer - CS c-sfr) # Vendor Homepage: glpi-projectorg # Software Link: glpi-projectorg/spipphp?article3 # Version: 0904 # Tested on: GLPI 0904 running on a Debian 7, Apache 222, MySQL 5549 ...
GLPI version 0904 suffers from a remote SQL injection vulnerability ...