CVE-2011-2720 Information

Description

The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields which allows remote attackers to obtain sensitive information via a crafted POST request.

Reference

http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063408.html http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063679.html http://secunia.com/advisories/45366 http://secunia.com/advisories/45542 http://www.glpi-project.org/spip.php?page=annonce&id_breve=237&lang=en http://www.mandriva.com/security/advisories?name=MDVSA-2012:014 http://www.openwall.com/lists/oss-security/2011/07/25/7 http://www.openwall.com/lists/oss-security/2011/07/26/11 http://www.securityfocus.com/bid/48884 https://bugzilla.redhat.com/show_bug.cgi?id=726185 https://forge.indepnet.net/issues/3017 https://forge.indepnet.net/projects/glpi/repository/revisions/14951 https://forge.indepnet.net/projects/glpi/repository/revisions/14952 https://forge.indepnet.net/projects/glpi/repository/revisions/14954 https://forge.indepnet.net/projects/glpi/repository/revisions/14955 https://forge.indepnet.net/projects/glpi/repository/revisions/14956 https://forge.indepnet.net/projects/glpi/repository/revisions/14957 https://forge.indepnet.net/projects/glpi/repository/revisions/14958 https://forge.indepnet.net/projects/glpi/repository/revisions/14960 https://forge.indepnet.net/projects/glpi/repository/revisions/14966 https://forge.indepnet.net/projects/glpi/versions/605

Share on: