VYPR

Glpi

by Glpi Project

Source repositories

CVEs (203)

  • CVE-2012-4002Oct 9, 2012
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2012-1037Jul 12, 2012
    risk 0.00cvss epss 0.01

    PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP code via a URL in the sub_type parameter.

  • CVE-2011-2720Aug 5, 2011
    risk 0.00cvss epss 0.03

    The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.

Page 11 of 11