CVE-2011-2720
05.08.2011, 21:55
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.Enginsight
Vendor | Product | Version |
---|---|---|
glpi-project | glpi | 𝑥 ≤ 0.80.1 |
glpi-project | glpi | 0.5 |
glpi-project | glpi | 0.5:rc1 |
glpi-project | glpi | 0.5:rc2 |
glpi-project | glpi | 0.6 |
glpi-project | glpi | 0.6:rc1 |
glpi-project | glpi | 0.6:rc2 |
glpi-project | glpi | 0.6:rc3 |
glpi-project | glpi | 0.42 |
glpi-project | glpi | 0.51 |
glpi-project | glpi | 0.51a:a |
glpi-project | glpi | 0.65 |
glpi-project | glpi | 0.65:rc1 |
glpi-project | glpi | 0.65:rc2 |
glpi-project | glpi | 0.68 |
glpi-project | glpi | 0.68:rc1 |
glpi-project | glpi | 0.68:rc2 |
glpi-project | glpi | 0.68:rc3 |
glpi-project | glpi | 0.68.1 |
glpi-project | glpi | 0.68.2 |
glpi-project | glpi | 0.68.3 |
glpi-project | glpi | 0.70 |
glpi-project | glpi | 0.70:rc1 |
glpi-project | glpi | 0.70:rc2 |
glpi-project | glpi | 0.70:rc3 |
glpi-project | glpi | 0.70.1 |
glpi-project | glpi | 0.70.2 |
glpi-project | glpi | 0.71 |
glpi-project | glpi | 0.71.1 |
glpi-project | glpi | 0.71.1:rc1 |
glpi-project | glpi | 0.71.1:rc2 |
glpi-project | glpi | 0.71.1:rc3 |
glpi-project | glpi | 0.71.2 |
glpi-project | glpi | 0.71.3 |
glpi-project | glpi | 0.71.4 |
glpi-project | glpi | 0.71.5 |
glpi-project | glpi | 0.71.6 |
glpi-project | glpi | 0.72 |
glpi-project | glpi | 0.72:rc1 |
glpi-project | glpi | 0.72:rc2 |
glpi-project | glpi | 0.72:rc3 |
glpi-project | glpi | 0.72.1 |
glpi-project | glpi | 0.72.2 |
glpi-project | glpi | 0.72.3 |
glpi-project | glpi | 0.72.4 |
glpi-project | glpi | 0.78 |
glpi-project | glpi | 0.78.1 |
glpi-project | glpi | 0.78.2 |
glpi-project | glpi | 0.78.3 |
glpi-project | glpi | 0.78.4 |
glpi-project | glpi | 0.78.5 |
glpi-project | glpi | 0.80 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References