GLPI Arbitrary File Upload and Privilege Escalation Vulnerability
BID:72686
Info
GLPI Arbitrary File Upload and Privilege Escalation Vulnerability
| Bugtraq ID: | 72686 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2015 12:00AM |
| Updated: | Feb 17 2015 12:00AM |
| Credit: | Peter STIEHL |
| Vulnerable: |
Glpi-Project Glpi 0.85.2 Glpi-Project Glpi 0.85.1 Glpi-Project Glpi 0.85 |
| Not Vulnerable: | |
Discussion
GLPI Arbitrary File Upload and Privilege Escalation Vulnerability
GLPI is prone to an arbitrary file upload vulnerability and a privilege escalation vulnerability.
A remote attacker can exploit this issue to execute arbitrary script code or perform unauthorized actions with elevated privileges.
GLPI Versions 0.85.2 and prior are vulnerable.
GLPI is prone to an arbitrary file upload vulnerability and a privilege escalation vulnerability.
A remote attacker can exploit this issue to execute arbitrary script code or perform unauthorized actions with elevated privileges.
GLPI Versions 0.85.2 and prior are vulnerable.
Exploit / POC
GLPI Arbitrary File Upload and Privilege Escalation Vulnerability
Attackers can use a readily available commands and tools to exploit this issue.
Attackers can use a readily available commands and tools to exploit this issue.
Solution / Fix
GLPI Arbitrary File Upload and Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.