CVE-2009-3040

Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.02:*:unix:*:*:*:*:*

History

07 Nov 2023, 02:04

Type Values Removed Values Added
References
  • {'url': 'http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=140&cntnt01returnid=72', 'name': 'http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=140&cntnt01returnid=72', 'tags': [], 'refsource': 'CONFIRM'}
  • () http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=140&cntnt01returnid=72 -

Information

Published : 2009-09-01 18:30

Updated : 2023-12-10 10:51


NVD link : CVE-2009-3040

Mitre link : CVE-2009-3040

CVE.ORG link : CVE-2009-3040


JSON object : View

Products Affected

ocsinventory-ng

  • ocs_inventory_ng
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')