CVE-2011-2720

The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
glpi-projectglpi
𝑥
≤ 0.80.1
glpi-projectglpi
0.5
glpi-projectglpi
0.5:rc1
glpi-projectglpi
0.5:rc2
glpi-projectglpi
0.6
glpi-projectglpi
0.6:rc1
glpi-projectglpi
0.6:rc2
glpi-projectglpi
0.6:rc3
glpi-projectglpi
0.42
glpi-projectglpi
0.51
glpi-projectglpi
0.51a:a
glpi-projectglpi
0.65
glpi-projectglpi
0.65:rc1
glpi-projectglpi
0.65:rc2
glpi-projectglpi
0.68
glpi-projectglpi
0.68:rc1
glpi-projectglpi
0.68:rc2
glpi-projectglpi
0.68:rc3
glpi-projectglpi
0.68.1
glpi-projectglpi
0.68.2
glpi-projectglpi
0.68.3
glpi-projectglpi
0.70
glpi-projectglpi
0.70:rc1
glpi-projectglpi
0.70:rc2
glpi-projectglpi
0.70:rc3
glpi-projectglpi
0.70.1
glpi-projectglpi
0.70.2
glpi-projectglpi
0.71
glpi-projectglpi
0.71.1
glpi-projectglpi
0.71.1:rc1
glpi-projectglpi
0.71.1:rc2
glpi-projectglpi
0.71.1:rc3
glpi-projectglpi
0.71.2
glpi-projectglpi
0.71.3
glpi-projectglpi
0.71.4
glpi-projectglpi
0.71.5
glpi-projectglpi
0.71.6
glpi-projectglpi
0.72
glpi-projectglpi
0.72:rc1
glpi-projectglpi
0.72:rc2
glpi-projectglpi
0.72:rc3
glpi-projectglpi
0.72.1
glpi-projectglpi
0.72.2
glpi-projectglpi
0.72.3
glpi-projectglpi
0.72.4
glpi-projectglpi
0.78
glpi-projectglpi
0.78.1
glpi-projectglpi
0.78.2
glpi-projectglpi
0.78.3
glpi-projectglpi
0.78.4
glpi-projectglpi
0.78.5
glpi-projectglpi
0.80
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glpi
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
ignored
References