Lädt...

🕵️ High CVE-2020-11060: Glpi-project GLPI


Nachrichtenbereich: 🕵️ Sicherheitslücken
🔗 Quelle: cxsecurity.com

In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a valid account by using a CSRF. Due to the difficulty of the exploitation, the attack is only conceivable by an account having Maintenance privileges and the right to add WIFI networks. This is fixed in version 9.4.6. ...

🕵️ http://glpi.paulista.pe.gov.br/glpi/kurd1943.html


📈 25.03 Punkte
🕵️ Hacking

🕵️ https://glpi.mairie-palaiseau.fr/glpi/


📈 25.03 Punkte
🕵️ Hacking

🕵️ https://glpi.hu-ufsc.ebserh.gov.br/glpi-cmsg/kurd.html


📈 25.03 Punkte
🕵️ Hacking

🕵️ http://glpi.ville-somain.fr/glpi/kurd.html


📈 25.03 Punkte
🕵️ Hacking

🕵️ CVE-2024-47760 | GLPI up to 10.0.16 API access control (GHSA-r3mx-fr5f-gwgp)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2023-28849 | GLPI up to 10.0.6 cross site scripting (GHSA-9r84-jpg3-h4m6)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ GLPI 0.90.4 cross site request forgery [CVE-2016-7507]


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-28241 | GLPI Agent up to 1.7.1 Installation privileges management


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2022-35914 | GLPI up to 10.0.2 htmlawed Module htmLawedTest.php code injection


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-47759 | GLPI up to 10.0.16 SVG cross site scripting (GHSA-474f-9vpp-xxq5)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ GLPI 0.90.4 Cross Site Request Forgery [CVE-2016-7507]


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-28240 | GLPI Agent up to 1.7.1 on Windows URL denial of service


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2022-36112 | GLPI up to 10.0.2 Planning server-side request forgery (GHSA-rqgx-gqhp-x8vv)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-50339 | GLPI up to 10.0.16 cross site scripting


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-31705 | GLPI 10.x Shell Commands Plugin os command injection


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2022-31187 | GLPI up to 10.0.2 Global Search cross site scripting (GHSA-43j5-xhvj-9236)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-48912 | GLPI up to 10.0.16 Application Endpoint access control (GHSA-vjmw-j32j-ph4f)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-27104 | GLPI up to 10.0.12 Dashboard cross site scripting


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2022-35945 | GLPI up to 10.0.2 Registration Key cross site scripting (GHSA-jrgw-cx24-56x5)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-48912 | GLPI up to 10.0.16 Application Endpoint access control (GHSA-vjmw-j32j-ph4f)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2023-22724 | GLPI up to 10.0.5 RSS Feed cross site scripting (GHSA-x9g4-j85w-cmff)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-27914 | GLPI up to 10.0.12 Debug Bar cross site scripting


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2022-35947 | GLPI up to 10.0.2 API sql injection (GHSA-7p3q-cffg-c8xh)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-27096 | GLPI up to 10.0.12 Search Engine sql injection


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2023-22725 | GLPI up to 10.0.5 cross site scripting (GHSA-f5g6-fxrw-pfj7)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2024-27098 | GLPI up to 10.0.12 server-side request forgery


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2022-31061 | GLPI Login Page sql injection (GHSA-w2gc-v2gm-q7wq)


📈 13.29 Punkte
🕵️ Sicherheitslücken

🕵️ CVE-2013-2226 | GLPI up to 0.83.31 table sql injection (EDB-26366 / Nessus ID 70132)


📈 13.29 Punkte
🕵️ Sicherheitslücken

matomo