OCS Inventory NG Multiple SQL Injection Vulnerabilities

Summary
This host is running OCS Inventory NG and is prone to multiple SQL injection vulnerabilities.
Impact
Successful exploitation will allow remote attackers to to view, add, modify or delete information in the back-end database. Impact Level: Application.
Solution
Upgrade to OCS Inventory NG version 1.02.3 For updates refer to http://www.ocsinventory-ng.org/
Insight
The flaws are due to the error in the 'index.php' page, which fails to properly varify the user supplied input via the 'search' form for the various inventory fields and via the All softwares search form for the 'Software name' field.
Affected
OCS Inventory NG prior to 1.02.3
References