Vulnerabilities
Vulnerable Software
Glpi-Project:  >> Glpi  >> 0.84.7  Security Vulnerabilities
Directory traversal vulnerability in inc/autoload.function.php in GLPI before 0.84.8 allows remote attackers to include and execute arbitrary local files via a .._ (dot dot underscore) in an item type to the getItemForItemtype, as demonstrated by the itemtype parameter in ajax/common.tabs.php.
CVSS Score
7.5
EPSS Score
0.01
Published
2015-04-14
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter.
CVSS Score
6.5
EPSS Score
0.069
Published
2014-12-19


Contact Us

Shodan ® - All rights reserved