HIGH
ocsinventory: multiple SQL injection vulnerabilities
Published Sep 1, 2009
7.5
HIGHCVSS 2.0
EPSS 1.42%
Description
Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.
Affected products
No data.
- 1.02
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_sql_injection.shtml x_refsource_MISCExploit
- http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=140&cntnt01returnid=72 x_refsource_CONFIRM
- http://www.securityfocus.com/archive/1/503936/100/0/threaded mailing-listx_refsource_BUGTRAQ
- https://access.redhat.com/security/cve/CVE-2009-3040 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=520687 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3024 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-3040
- https://www.cve.org/CVERecord?id=CVE-2009-3040
| Link | Providers | Tags |
|---|---|---|
| http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_sql_injection.shtml | x_refsource_MISCExploit | |
| http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=140&cntnt01returnid=72 | x_refsource_CONFIRM | |
| http://www.securityfocus.com/archive/1/503936/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| https://access.redhat.com/security/cve/CVE-2009-3040 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=520687 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3024 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-3040 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-3040 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 1, 2009
Updated Aug 7, 2024
Reserved Sep 1, 2009
Link CVE-2009-3040
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-3024 Assigner mitre
Published Sep 1, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-3024