Back to search
CVE-2013-5696
Published: Sep 23, 2013
Modified: Sep 16, 2024
PUBLISHED
Description
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://forge.indepnet.net/issues/4480
x_refsource_CONFIRM
https://forge.indepnet.net/projects/glpi/repository/revisions/21753
x_refsource_CONFIRM
http://www.glpi-project.org/spip.php?page=annonce&id_breve=308
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now