Summary
This host is running OCS Inventory NG and is prone to multiple SQL injection vulnerabilities.
Impact
Successful exploitation will allow remote attackers to to view, add, modify or delete information in the back-end database.
Impact Level: Application.
Solution
Upgrade to OCS Inventory NG version 1.02.3
For updates refer to http://www.ocsinventory-ng.org/
Insight
The flaws are due to the error in the 'index.php' page, which fails to properly varify the user supplied input via the 'search' form for the various inventory fields and via the All softwares search form for the 'Software name' field.
Affected
OCS Inventory NG prior to 1.02.3
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2010-1733 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities