Vulnerabilities > Glpi Project > Glpi > 0.83.31

DATE CVE VULNERABILITY TITLE RISK
2018-03-12 CVE-2018-7562 Race Condition vulnerability in Glpi-Project Glpi
A remote code execution issue was discovered in GLPI through 9.2.1.
6.0
2017-07-28 CVE-2017-11184 SQL Injection vulnerability in Glpi-Project Glpi
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
network
low complexity
glpi-project CWE-89
7.5
2017-07-28 CVE-2017-11183 Improper Input Validation vulnerability in Glpi-Project Glpi
front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.
network
low complexity
glpi-project CWE-20
5.5
2017-07-20 CVE-2017-11475 SQL Injection vulnerability in Glpi-Project Glpi
GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.
network
low complexity
glpi-project CWE-89
6.5
2017-07-20 CVE-2017-11474 SQL Injection vulnerability in Glpi-Project Glpi
GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php.
network
low complexity
glpi-project CWE-89
7.5
2017-07-17 CVE-2017-11329 SQL Injection vulnerability in Glpi-Project Glpi
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.
network
low complexity
glpi-project CWE-89
7.5
2015-10-05 CVE-2015-7685 Permissions, Privileges, and Access Controls vulnerability in Glpi-Project Glpi
GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.
network
low complexity
glpi-project CWE-264
4.0
2015-10-05 CVE-2015-7684 Unspecified vulnerability in Glpi-Project Glpi
Unrestricted file upload in GLPI before 0.85.3 allows remote authenticated users to execute arbitrary code by adding a file with an executable extension as an attachment to a new ticket, then accessing it via a direct request to the file in files/_tmp/.
network
low complexity
glpi-project
critical
9.0
2015-04-14 CVE-2014-8360 Path Traversal vulnerability in Glpi-Project Glpi
Directory traversal vulnerability in inc/autoload.function.php in GLPI before 0.84.8 allows remote attackers to include and execute arbitrary local files via a .._ (dot dot underscore) in an item type to the getItemForItemtype, as demonstrated by the itemtype parameter in ajax/common.tabs.php.
network
low complexity
glpi-project CWE-22
7.5
2015-04-14 CVE-2014-5032 Permissions, Privileges, and Access Controls vulnerability in Glpi-Project Glpi
GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensitive information via the cost criteria in the search bar.
network
low complexity
glpi-project CWE-264
5.0