First published: Wed Jun 21 2017(Updated: )
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Teclib GLPI | =0.90.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7508 is classified as a medium severity vulnerability due to its potential for SQL injection attacks.
To fix CVE-2016-7508, upgrade GLPI to a version later than 0.90.4 that addresses the SQL injection vulnerabilities.
CVE-2016-7508 can be exploited by authenticated remote attackers to execute arbitrary SQL commands.
The only affected version identified by CVE-2016-7508 is GLPI version 0.90.4.
CVE-2016-7508 specifically targets systems configured to use Big5 Asian encoding for their databases.