Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP code via a URL in the sub_type parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GLPI ‘sub_type’ 远程文件包含漏洞
Vulnerability Description
GLPI是Indepnet协会维护的一款开源的IT资源管理套件。该套件包含设备状态管理、资产清单存储、管理流程和工作日志管理等功能。 GLPI 0.78至0.80.61之间的版本中存在PHP远程文件包含漏洞,该漏洞源于对用户提供的输入未经充分过滤。攻击者可利用该漏洞在受影响应用程序上下文中包含并执行任意远程文件和恶意PHP代码,这将有助于操控应用程序和底层系统,也可能执行其他攻击。
CVSS Information
N/A
Vulnerability Type
N/A