CVE-2009-3040: SQL Injection
Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to groupshow.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3040?
CVE-2009-3040 is classified as a medium severity vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2009-3040?
To mitigate CVE-2009-3040, it is recommended to upgrade to a patched version of OCS Inventory NG beyond 1.02.
What software versions are affected by CVE-2009-3040?
CVE-2009-3040 affects OCS Inventory NG version 1.02 for Unix.
Can CVE-2009-3040 be exploited remotely?
Yes, CVE-2009-3040 can be exploited remotely by attackers to execute arbitrary SQL commands.
What parameters are vulnerable in CVE-2009-3040?
The vulnerable parameters in CVE-2009-3040 include N, DL, O, V in download.php and SYSTEMID in group_show.php.