PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP code via a URL in the sub_type parameter.
2012-07-12T20:55:10.873
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | glpi-project | glpi | 0.78 | Yes |
Application | glpi-project | glpi | 0.78.1 | Yes |
Application | glpi-project | glpi | 0.78.2 | Yes |
Application | glpi-project | glpi | 0.78.3 | Yes |
Application | glpi-project | glpi | 0.78.4 | Yes |
Application | glpi-project | glpi | 0.78.5 | Yes |
Application | glpi-project | glpi | 0.80 | Yes |
Application | glpi-project | glpi | 0.80.1 | Yes |
Application | glpi-project | glpi | 0.80.2 | Yes |
Application | glpi-project | glpi | 0.80.3 | Yes |
Application | glpi-project | glpi | 0.80.4 | Yes |
Application | glpi-project | glpi | 0.80.5 | Yes |
Application | glpi-project | glpi | 0.80.6 | Yes |
Application | glpi-project | glpi | 0.80.61 | Yes |