First published: Tue Sep 01 2009(Updated: )
Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OCS Inventory NG | =1.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3040 is classified as a medium severity vulnerability due to the potential for remote SQL injection attacks.
To mitigate CVE-2009-3040, it is recommended to upgrade to a patched version of OCS Inventory NG beyond 1.02.
CVE-2009-3040 affects OCS Inventory NG version 1.02 for Unix.
Yes, CVE-2009-3040 can be exploited remotely by attackers to execute arbitrary SQL commands.
The vulnerable parameters in CVE-2009-3040 include N, DL, O, V in download.php and SYSTEMID in group_show.php.