CVE-2013-2226
Publication date 14 May 2014
Last updated 24 July 2024
Ubuntu priority
Description
Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to ajax/comments.php.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| glpi | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |