CVE-2009-3040

Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.02:*:unix:*:*:*:*:*

History

21 Nov 2024, 01:06

Type Values Removed Values Added
References () http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_sql_injection.shtml - Exploit () http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_sql_injection.shtml - Exploit
References () http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=140&cntnt01returnid=72 - () http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=140&cntnt01returnid=72 -
References () http://www.securityfocus.com/archive/1/503936/100/0/threaded - () http://www.securityfocus.com/archive/1/503936/100/0/threaded -

07 Nov 2023, 02:04

Type Values Removed Values Added
References
  • {'url': 'http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=140&cntnt01returnid=72', 'name': 'http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=140&cntnt01returnid=72', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=140&cntnt01returnid=72 -

Information

Published : 2009-09-01 18:30

Updated : 2024-11-21 01:06


NVD link : CVE-2009-3040

Mitre link : CVE-2009-3040

CVE.ORG link : CVE-2009-3040


JSON object : View

Products Affected

ocsinventory-ng

  • ocs_inventory_ng
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')