CVE-2011-2720

EUVD-2011-2698
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
Affected Products (NVD)
VendorProductVersion
glpi-projectglpi
𝑥
≤ 0.80.1
glpi-projectglpi
0.5
glpi-projectglpi
0.5:rc1
glpi-projectglpi
0.5:rc2
glpi-projectglpi
0.6
glpi-projectglpi
0.6:rc1
glpi-projectglpi
0.6:rc2
glpi-projectglpi
0.6:rc3
glpi-projectglpi
0.42
glpi-projectglpi
0.51
glpi-projectglpi
0.51a:a
glpi-projectglpi
0.65
glpi-projectglpi
0.65:rc1
glpi-projectglpi
0.65:rc2
glpi-projectglpi
0.68
glpi-projectglpi
0.68:rc1
glpi-projectglpi
0.68:rc2
glpi-projectglpi
0.68:rc3
glpi-projectglpi
0.68.1
glpi-projectglpi
0.68.2
glpi-projectglpi
0.68.3
glpi-projectglpi
0.70
glpi-projectglpi
0.70:rc1
glpi-projectglpi
0.70:rc2
glpi-projectglpi
0.70:rc3
glpi-projectglpi
0.70.1
glpi-projectglpi
0.70.2
glpi-projectglpi
0.71
glpi-projectglpi
0.71.1
glpi-projectglpi
0.71.1:rc1
glpi-projectglpi
0.71.1:rc2
glpi-projectglpi
0.71.1:rc3
glpi-projectglpi
0.71.2
glpi-projectglpi
0.71.3
glpi-projectglpi
0.71.4
glpi-projectglpi
0.71.5
glpi-projectglpi
0.71.6
glpi-projectglpi
0.72
glpi-projectglpi
0.72:rc1
glpi-projectglpi
0.72:rc2
glpi-projectglpi
0.72:rc3
glpi-projectglpi
0.72.1
glpi-projectglpi
0.72.2
glpi-projectglpi
0.72.3
glpi-projectglpi
0.72.4
glpi-projectglpi
0.78
glpi-projectglpi
0.78.1
glpi-projectglpi
0.78.2
glpi-projectglpi
0.78.3
glpi-projectglpi
0.78.4
glpi-projectglpi
0.78.5
glpi-projectglpi
0.80
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glpi
hardy
ignored
lucid
ignored
maverick
ignored
natty
ignored
oneiric
ignored
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
References