CVE-2009-3040
Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.42% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- ocsinventory-ng/ocs inventory ng
- Source
- cve@mitre.org
References
- http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_sql_injection.shtmlExploit
- http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=140&cntnt01returnid=72
- http://www.securityfocus.com/archive/1/503936/100/0/threaded
- http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_sql_injection.shtmlExploit
- http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=140&cntnt01returnid=72
- http://www.securityfocus.com/archive/1/503936/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.