GLPI 'unserialize()' Function Remote PHP Code Execution Vulnerability
BID:60823
Info
GLPI 'unserialize()' Function Remote PHP Code Execution Vulnerability
| Bugtraq ID: | 60823 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2225 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2013 12:00AM |
| Updated: | Apr 13 2015 10:09PM |
| Credit: | Xavier Mehrenberger |
| Vulnerable: |
Glpi-Project Glpi 0.83.9 |
| Not Vulnerable: |
Glpi-Project Glpi 0.83.91 |
Discussion
GLPI 'unserialize()' Function Remote PHP Code Execution Vulnerability
GLPI is prone to a remote PHP code-execution vulnerability.
An attacker can exploit this issue to inject and execute arbitrary PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
GLPI 0.83.9 is vulnerable; other versions may also be affected.
GLPI is prone to a remote PHP code-execution vulnerability.
An attacker can exploit this issue to inject and execute arbitrary PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
GLPI 0.83.9 is vulnerable; other versions may also be affected.
Exploit / POC
GLPI 'unserialize()' Function Remote PHP Code Execution Vulnerability
An attacker can exploit this issue using a web browser.
The following example URI is available:
http://www.example.com/glpi/front/ticket.form.php?id=1&_predefined_fields=[XXXX]
An attacker can exploit this issue using a web browser.
The following example URI is available:
http://www.example.com/glpi/front/ticket.form.php?id=1&_predefined_fields=[XXXX]