|
|
| |
|
| |
glpi: information disclosure
| Package(s): | glpi |
CVE #(s): | CVE-2011-2720
|
| Created: | August 4, 2011 |
Updated: | February 7, 2012 |
| Description: |
From the Red Hat Bugzilla entry:
It was found that GLPI, the Information Resource-Manager with an additional
Administration-Interface, did not properly blacklist certain sensitive
variables (like GLPI username and password). A remote attacker could use this
flaw to obtain access to plaintext form of these values via specially-crafted
HTTP POST request.
|
| Alerts: |
|
( Log in to post comments)
|
|
|