Short Name |
HTTP:GLPI-INSTALLPHP-RCE
|
Severity |
High
|
Recommended |
Yes
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
GLPI install.php Script Arbitrary Command and SQL Injection
|
Release Date |
2013/11/25
|
Update Number |
2322
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: GLPI install.php Script Arbitrary Command and SQL Injection
This signature detects attempts to exploit a known vulnerability against GLPI web application. It is due to insufficient validation of user-supplied input. Attackers can execute arbitrary commands or submit malicious SQL statements to the underlying database.
Extended Description
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action.
Affected Products
- glpi-project glpi 0.20
- glpi-project glpi 0.21
- glpi-project glpi 0.30
- glpi-project glpi 0.31
- glpi-project glpi 0.40
- glpi-project glpi 0.41
- glpi-project glpi 0.42
- glpi-project glpi 0.51
- glpi-project glpi 0.51a
- glpi-project glpi 0.5 (rc1)
- glpi-project glpi 0.5 (rc2)
- glpi-project glpi 0.65 (rc1)
- glpi-project glpi 0.65 (rc2)
- glpi-project glpi 0.68.1
- glpi-project glpi 0.68.2
- glpi-project glpi 0.68.3
- glpi-project glpi 0.68 (rc1)
- glpi-project glpi 0.68 (rc2)
- glpi-project glpi 0.68 (rc3)
- glpi-project glpi 0.6 (rc1)
- glpi-project glpi 0.6 (rc2)
- glpi-project glpi 0.6 (rc3)
- glpi-project glpi 0.70.1
- glpi-project glpi 0.70.2
- glpi-project glpi 0.70 (rc1)
- glpi-project glpi 0.70 (rc2)
- glpi-project glpi 0.70 (rc3)
- glpi-project glpi 0.71
- glpi-project glpi 0.71.1 (rc1)
- glpi-project glpi 0.71.1 (rc2)
- glpi-project glpi 0.71.1 (rc3)
- glpi-project glpi 0.71.2
- glpi-project glpi 0.71.3
- glpi-project glpi 0.71.4
- glpi-project glpi 0.71.5
- glpi-project glpi 0.71.6
- glpi-project glpi 0.72.1
- glpi-project glpi 0.72.2
- glpi-project glpi 0.72.3
- glpi-project glpi 0.72.4
- glpi-project glpi 0.72 (rc1)
- glpi-project glpi 0.72 (rc2)
- glpi-project glpi 0.72 (rc3)
- glpi-project glpi 0.78
- glpi-project glpi 0.78.1
- glpi-project glpi 0.78.2
- glpi-project glpi 0.78.3
- glpi-project glpi 0.78.4
- glpi-project glpi 0.78.5
- glpi-project glpi 0.80
- glpi-project glpi 0.80.1
- glpi-project glpi 0.80.2
- glpi-project glpi 0.80.3
- glpi-project glpi 0.80.4
- glpi-project glpi 0.80.5
- glpi-project glpi 0.80.6
- glpi-project glpi 0.80.61
- glpi-project glpi 0.80.7
- glpi-project glpi 0.83
- glpi-project glpi 0.83.1
- glpi-project glpi 0.83.2
- glpi-project glpi 0.83.3
- glpi-project glpi 0.83.31
- glpi-project glpi 0.83.4
- glpi-project glpi 0.83.5
- glpi-project glpi 0.83.6
- glpi-project glpi 0.83.7
- glpi-project glpi 0.83.8
- glpi-project glpi 0.83.9
- glpi-project glpi 0.83.91
- glpi-project glpi 0.84
- glpi-project glpi up to 0.84.1
References