5
CVE-2011-2720
- EPSS 1.02%
- Veröffentlicht 05.08.2011 21:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Glpi-project ≫ Glpi Version <= 0.80.1
Glpi-project ≫ Glpi Version0.5
Glpi-project ≫ Glpi Version0.5 Updaterc1
Glpi-project ≫ Glpi Version0.5 Updaterc2
Glpi-project ≫ Glpi Version0.6
Glpi-project ≫ Glpi Version0.6 Updaterc1
Glpi-project ≫ Glpi Version0.6 Updaterc2
Glpi-project ≫ Glpi Version0.6 Updaterc3
Glpi-project ≫ Glpi Version0.42
Glpi-project ≫ Glpi Version0.51
Glpi-project ≫ Glpi Version0.51a
Glpi-project ≫ Glpi Version0.65
Glpi-project ≫ Glpi Version0.65 Updaterc1
Glpi-project ≫ Glpi Version0.65 Updaterc2
Glpi-project ≫ Glpi Version0.68
Glpi-project ≫ Glpi Version0.68 Updaterc1
Glpi-project ≫ Glpi Version0.68 Updaterc2
Glpi-project ≫ Glpi Version0.68 Updaterc3
Glpi-project ≫ Glpi Version0.68.1
Glpi-project ≫ Glpi Version0.68.2
Glpi-project ≫ Glpi Version0.68.3
Glpi-project ≫ Glpi Version0.70
Glpi-project ≫ Glpi Version0.70 Updaterc1
Glpi-project ≫ Glpi Version0.70 Updaterc2
Glpi-project ≫ Glpi Version0.70 Updaterc3
Glpi-project ≫ Glpi Version0.70.1
Glpi-project ≫ Glpi Version0.70.2
Glpi-project ≫ Glpi Version0.71
Glpi-project ≫ Glpi Version0.71.1
Glpi-project ≫ Glpi Version0.71.1 Updaterc1
Glpi-project ≫ Glpi Version0.71.1 Updaterc2
Glpi-project ≫ Glpi Version0.71.1 Updaterc3
Glpi-project ≫ Glpi Version0.71.2
Glpi-project ≫ Glpi Version0.71.3
Glpi-project ≫ Glpi Version0.71.4
Glpi-project ≫ Glpi Version0.71.5
Glpi-project ≫ Glpi Version0.71.6
Glpi-project ≫ Glpi Version0.72
Glpi-project ≫ Glpi Version0.72 Updaterc1
Glpi-project ≫ Glpi Version0.72 Updaterc2
Glpi-project ≫ Glpi Version0.72 Updaterc3
Glpi-project ≫ Glpi Version0.72.1
Glpi-project ≫ Glpi Version0.72.2
Glpi-project ≫ Glpi Version0.72.3
Glpi-project ≫ Glpi Version0.72.4
Glpi-project ≫ Glpi Version0.78
Glpi-project ≫ Glpi Version0.78.1
Glpi-project ≫ Glpi Version0.78.2
Glpi-project ≫ Glpi Version0.78.3
Glpi-project ≫ Glpi Version0.78.4
Glpi-project ≫ Glpi Version0.78.5
Glpi-project ≫ Glpi Version0.80
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.02% | 0.752 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.