7.5
CVSSv2

CVE-2009-3040

Published: 01/09/2009 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote malicious users to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ocsinventory-ng ocs inventory ng 1.02

Exploits

OCS Inventory NG - Multiple SQL Injections (May 30 2009) _______________________________________________________________________________ * Product Open Computer and Software (OCS) Inventory NG (wwwocsinventory-ngorg/) * Vulnerable Versions OCS Inventory NG 102 (Unix) * Vendor Status Vendor has been notified and the vulnera ...