LWN.net Logo

glpi: file inclusion vulnerability

Package(s):glpi CVE #(s):CVE-2012-1037
Created:February 13, 2012 Updated:February 20, 2012
Description: GLPI v 0.78 to 0.80.61 fails to properly sanitize the GET 'sub_type' parameter in the front/popup.php file. This has been fixed in GLPI 0.80.7. See this post on the Full Disclosure mailing list for additional details.
Alerts:
Mandriva MDVSA-2012:016 2012-02-10
Fedora FEDORA-2012-1519 2012-02-19
Fedora FEDORA-2012-1534 2012-02-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds