Unrated severityNVD Advisory· Published Aug 5, 2011· Updated Apr 29, 2026
CVE-2011-2720
CVE-2011-2720
Description
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
Affected products
52cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*+ 51 more
- cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*:*range: <=0.80.1
- cpe:2.3:a:glpi-project:glpi:0.5:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.5:rc1:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.5:rc2:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.6:rc1:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.6:rc2:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.6:rc3:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.42:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.51:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.51a:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.65:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.65:rc1:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.65:rc2:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.68:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.68:rc1:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.68:rc2:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.68:rc3:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.68.1:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.68.2:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.68.3:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.70:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.70:rc1:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.70:rc2:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.70:rc3:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.70.1:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.70.2:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.71:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.71.1:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.71.1:rc1:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.71.1:rc2:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.71.1:rc3:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.71.2:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.71.3:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.71.4:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.71.5:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.71.6:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.72:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.72:rc1:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.72:rc2:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.72:rc3:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.72.1:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.72.2:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.72.3:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.72.4:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.78:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.78.1:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.78.2:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.78.3:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.78.4:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.78.5:*:*:*:*:*:*:*
- cpe:2.3:a:glpi-project:glpi:0.80:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
21- www.openwall.com/lists/oss-security/2011/07/25/7nvdPatch
- www.openwall.com/lists/oss-security/2011/07/26/11nvdPatch
- bugzilla.redhat.com/show_bug.cginvdPatch
- forge.indepnet.net/projects/glpi/repository/revisions/14951nvdPatch
- forge.indepnet.net/projects/glpi/repository/revisions/14952nvdPatch
- forge.indepnet.net/projects/glpi/repository/revisions/14954nvdPatch
- forge.indepnet.net/projects/glpi/repository/revisions/14955nvdPatch
- forge.indepnet.net/projects/glpi/repository/revisions/14956nvdPatch
- forge.indepnet.net/projects/glpi/repository/revisions/14957nvdPatch
- forge.indepnet.net/projects/glpi/repository/revisions/14958nvdPatch
- forge.indepnet.net/projects/glpi/repository/revisions/14960nvdPatch
- forge.indepnet.net/projects/glpi/repository/revisions/14966nvdPatch
- secunia.com/advisories/45366nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2011-August/063408.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-August/063679.htmlnvd
- secunia.com/advisories/45542nvd
- www.glpi-project.org/spip.phpnvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/48884nvd
- forge.indepnet.net/issues/3017nvd
- forge.indepnet.net/projects/glpi/versions/605nvd
News mentions
0No linked articles in our index yet.