| MDVSA-2012:014: glpi |
|
|
|
| Écrit par Administrator |
| Mardi, 07 Février 2012 00:00 |
|
A vulnerability has been found and corrected in GLPI:
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request (CVE-2011-2720). This advisory provides the latest version of GLPI (0.80.6) which are not vulnerable to this issue. Additionally the latest versions of the corresponding plugins are also being provided. |




























































