header-logo
Suggest Exploit
vendor:
GLPI
by:
High-Tech Bridge Security Research Lab
6,4
CVSS
CRITICAL
Improper Access Control [CWE-284],Code Injection [CWE-94]
284, 94
CWE
Product Name: GLPI
Affected Version From: 0.84.1
Affected Version To: 0.84.1
Patch Exists: YES
Related CWE: CVE-2013-5696
CPE: a:indepnet:glpi
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013

Advisory ID: HTB23173

The vulnerability exists due to insufficient access restrictions to the installation script "/install/install.php", which is present by default after application installation. A remote attacker can change applicationâ??s configuration, such as database host, forcing the application to connect to an external database and spoof information on the website, obtain access to sensitive information or simply cause a denial of service. The vulnerability exists due to insufficient validation of user-supplied input passed to the "db_host", "db_user", "db_pass", a "db_prefix" parameters in the "/install/install.php" script. A remote attacker can inject and execute arbitrary PHP code with privileges of web server.

Mitigation:

Fixed by Vendor
Source

Exploit-DB raw data: