Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 27 Jun 2013 18:04:51 +0200
From: Raphael Geissert <>
Subject: CVE request: GLPI, multiple issues


[CC'ing upstream for complimentary information]

Multiple SQL injections have been reported in GLPI:

(note that the original advisory was hosted at but
it 404s as of the time of writing)

And a local file inclusion vulnerability was also reported:

(same note as for the above issue)

I'm not aware of related commits or bug reports other than the
following (but this is me trying to connect dots):
which was marked as fixed at least in (0.83.9):
But the bug report also refers to the fix in trunk and the 0.85 branch.

Could CVE ids be assigned please?

Note that this is a different request than the one for the one about
the use of unserialize on untrusted data.

Thanks in advance,
Raphael Geissert - Debian Developer -

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.