github.com
https://github.com/glpi-project/glpi/issues/1047 CVE-2016-7508
HIGH
GLPI 0.90.4 - SQL Injection
Record summary
CVE-2016-7508 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGLPI 0.90.4 - SQL InjectionExploitDB exploitby Eric CARTERNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-7508 42262exploit
https://www.exploit-db.com/exploits/42262