Lucene search

K
cveMitreCVE-2010-1733
HistoryMay 06, 2010 - 12:47 p.m.

CVE-2010-1733

2010-05-0612:47:23
CWE-89
mitre
web.nvd.nist.gov
39
ocs inventory ng
sql injection
vulnerability
remote attackers
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8.2

Confidence

Low

EPSS

0.001

Percentile

49.0%

Multiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search form, reachable through index.php; or (2) the “Software name” field to the “All softwares” search form, reachable through index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected configurations

Nvd
Node
ocsinventory-ngocs_inventory_ngRange1.02.1
OR
ocsinventory-ngocs_inventory_ngMatch1.0beta
OR
ocsinventory-ngocs_inventory_ngMatch1.0rc1
OR
ocsinventory-ngocs_inventory_ngMatch1.0rc2
OR
ocsinventory-ngocs_inventory_ngMatch1.0rc3
OR
ocsinventory-ngocs_inventory_ngMatch1.0rc3-1
OR
ocsinventory-ngocs_inventory_ngMatch1.01
OR
ocsinventory-ngocs_inventory_ngMatch1.02
OR
ocsinventory-ngocs_inventory_ngMatch1.02unix
OR
ocsinventory-ngocs_inventory_ngMatch1.02rc1
OR
ocsinventory-ngocs_inventory_ngMatch1.02rc2
OR
ocsinventory-ngocs_inventory_ngMatch1.02rc3
VendorProductVersionCPE
ocsinventory-ngocs_inventory_ng*cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:*:*:*:*:*:*:*:*
ocsinventory-ngocs_inventory_ng1.0cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.0:beta:*:*:*:*:*:*
ocsinventory-ngocs_inventory_ng1.0cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.0:rc1:*:*:*:*:*:*
ocsinventory-ngocs_inventory_ng1.0cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.0:rc2:*:*:*:*:*:*
ocsinventory-ngocs_inventory_ng1.0cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.0:rc3:*:*:*:*:*:*
ocsinventory-ngocs_inventory_ng1.0cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.0:rc3-1:*:*:*:*:*:*
ocsinventory-ngocs_inventory_ng1.01cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.01:*:*:*:*:*:*:*
ocsinventory-ngocs_inventory_ng1.02cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.02:*:*:*:*:*:*:*
ocsinventory-ngocs_inventory_ng1.02cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.02:*:unix:*:*:*:*:*
ocsinventory-ngocs_inventory_ng1.02cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.02:rc1:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8.2

Confidence

Low

EPSS

0.001

Percentile

49.0%