Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:GLPI-INSTALLPHP-RCE

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

GLPI install.php Script Arbitrary Command and SQL Injection

Release Date

2013/11/25

Update Number

2322

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: GLPI install.php Script Arbitrary Command and SQL Injection


This signature detects attempts to exploit a known vulnerability against GLPI web application. It is due to insufficient validation of user-supplied input. Attackers can execute arbitrary commands or submit malicious SQL statements to the underlying database.

Extended Description

inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action.

Affected Products

  • glpi-project glpi 0.20
  • glpi-project glpi 0.21
  • glpi-project glpi 0.30
  • glpi-project glpi 0.31
  • glpi-project glpi 0.40
  • glpi-project glpi 0.41
  • glpi-project glpi 0.42
  • glpi-project glpi 0.51
  • glpi-project glpi 0.51a
  • glpi-project glpi 0.5 (rc1)
  • glpi-project glpi 0.5 (rc2)
  • glpi-project glpi 0.65 (rc1)
  • glpi-project glpi 0.65 (rc2)
  • glpi-project glpi 0.68.1
  • glpi-project glpi 0.68.2
  • glpi-project glpi 0.68.3
  • glpi-project glpi 0.68 (rc1)
  • glpi-project glpi 0.68 (rc2)
  • glpi-project glpi 0.68 (rc3)
  • glpi-project glpi 0.6 (rc1)
  • glpi-project glpi 0.6 (rc2)
  • glpi-project glpi 0.6 (rc3)
  • glpi-project glpi 0.70.1
  • glpi-project glpi 0.70.2
  • glpi-project glpi 0.70 (rc1)
  • glpi-project glpi 0.70 (rc2)
  • glpi-project glpi 0.70 (rc3)
  • glpi-project glpi 0.71
  • glpi-project glpi 0.71.1 (rc1)
  • glpi-project glpi 0.71.1 (rc2)
  • glpi-project glpi 0.71.1 (rc3)
  • glpi-project glpi 0.71.2
  • glpi-project glpi 0.71.3
  • glpi-project glpi 0.71.4
  • glpi-project glpi 0.71.5
  • glpi-project glpi 0.71.6
  • glpi-project glpi 0.72.1
  • glpi-project glpi 0.72.2
  • glpi-project glpi 0.72.3
  • glpi-project glpi 0.72.4
  • glpi-project glpi 0.72 (rc1)
  • glpi-project glpi 0.72 (rc2)
  • glpi-project glpi 0.72 (rc3)
  • glpi-project glpi 0.78
  • glpi-project glpi 0.78.1
  • glpi-project glpi 0.78.2
  • glpi-project glpi 0.78.3
  • glpi-project glpi 0.78.4
  • glpi-project glpi 0.78.5
  • glpi-project glpi 0.80
  • glpi-project glpi 0.80.1
  • glpi-project glpi 0.80.2
  • glpi-project glpi 0.80.3
  • glpi-project glpi 0.80.4
  • glpi-project glpi 0.80.5
  • glpi-project glpi 0.80.6
  • glpi-project glpi 0.80.61
  • glpi-project glpi 0.80.7
  • glpi-project glpi 0.83
  • glpi-project glpi 0.83.1
  • glpi-project glpi 0.83.2
  • glpi-project glpi 0.83.3
  • glpi-project glpi 0.83.31
  • glpi-project glpi 0.83.4
  • glpi-project glpi 0.83.5
  • glpi-project glpi 0.83.6
  • glpi-project glpi 0.83.7
  • glpi-project glpi 0.83.8
  • glpi-project glpi 0.83.9
  • glpi-project glpi 0.83.91
  • glpi-project glpi 0.84
  • glpi-project glpi up to 0.84.1

References

  • CVE: CVE-2013-5696

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out