The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
2011-08-05T21:55:06.107
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | glpi-project | glpi | ≤ 0.80.1 | Yes |
Application | glpi-project | glpi | 0.5 | Yes |
Application | glpi-project | glpi | 0.5 | Yes |
Application | glpi-project | glpi | 0.5 | Yes |
Application | glpi-project | glpi | 0.6 | Yes |
Application | glpi-project | glpi | 0.6 | Yes |
Application | glpi-project | glpi | 0.6 | Yes |
Application | glpi-project | glpi | 0.6 | Yes |
Application | glpi-project | glpi | 0.42 | Yes |
Application | glpi-project | glpi | 0.51 | Yes |
Application | glpi-project | glpi | 0.51a | Yes |
Application | glpi-project | glpi | 0.65 | Yes |
Application | glpi-project | glpi | 0.65 | Yes |
Application | glpi-project | glpi | 0.65 | Yes |
Application | glpi-project | glpi | 0.68 | Yes |
Application | glpi-project | glpi | 0.68 | Yes |
Application | glpi-project | glpi | 0.68 | Yes |
Application | glpi-project | glpi | 0.68 | Yes |
Application | glpi-project | glpi | 0.68.1 | Yes |
Application | glpi-project | glpi | 0.68.2 | Yes |
Application | glpi-project | glpi | 0.68.3 | Yes |
Application | glpi-project | glpi | 0.70 | Yes |
Application | glpi-project | glpi | 0.70 | Yes |
Application | glpi-project | glpi | 0.70 | Yes |
Application | glpi-project | glpi | 0.70 | Yes |
Application | glpi-project | glpi | 0.70.1 | Yes |
Application | glpi-project | glpi | 0.70.2 | Yes |
Application | glpi-project | glpi | 0.71 | Yes |
Application | glpi-project | glpi | 0.71.1 | Yes |
Application | glpi-project | glpi | 0.71.1 | Yes |
Application | glpi-project | glpi | 0.71.1 | Yes |
Application | glpi-project | glpi | 0.71.1 | Yes |
Application | glpi-project | glpi | 0.71.2 | Yes |
Application | glpi-project | glpi | 0.71.3 | Yes |
Application | glpi-project | glpi | 0.71.4 | Yes |
Application | glpi-project | glpi | 0.71.5 | Yes |
Application | glpi-project | glpi | 0.71.6 | Yes |
Application | glpi-project | glpi | 0.72 | Yes |
Application | glpi-project | glpi | 0.72 | Yes |
Application | glpi-project | glpi | 0.72 | Yes |
Application | glpi-project | glpi | 0.72 | Yes |
Application | glpi-project | glpi | 0.72.1 | Yes |
Application | glpi-project | glpi | 0.72.2 | Yes |
Application | glpi-project | glpi | 0.72.3 | Yes |
Application | glpi-project | glpi | 0.72.4 | Yes |
Application | glpi-project | glpi | 0.78 | Yes |
Application | glpi-project | glpi | 0.78.1 | Yes |
Application | glpi-project | glpi | 0.78.2 | Yes |
Application | glpi-project | glpi | 0.78.3 | Yes |
Application | glpi-project | glpi | 0.78.4 | Yes |
Application | glpi-project | glpi | 0.78.5 | Yes |
Application | glpi-project | glpi | 0.80 | Yes |