LWN.net Logo

glpi: information disclosure

Package(s):glpi CVE #(s):CVE-2011-2720
Created:August 4, 2011 Updated:February 7, 2012
Description:

From the Red Hat Bugzilla entry:

It was found that GLPI, the Information Resource-Manager with an additional Administration-Interface, did not properly blacklist certain sensitive variables (like GLPI username and password). A remote attacker could use this flaw to obtain access to plaintext form of these values via specially-crafted HTTP POST request.

Alerts:
Fedora FEDORA-2011-9690 2011-07-26
Fedora FEDORA-2011-9690 2011-07-26
Fedora FEDORA-2011-9690 2011-07-26
Fedora FEDORA-2011-9690 2011-07-26
Fedora FEDORA-2011-9639 2011-07-23
Mandriva MDVSA-2012:014 2012-02-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds