First published: Wed Apr 28 2010(Updated: )
Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3) onglet_bis parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OCS Inventory NG | =1.02.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1595 is considered a medium severity SQL injection vulnerability that can allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2010-1595, upgrade OCS Inventory NG to a version newer than 1.02.1 that contains the necessary security patches.
CVE-2010-1595 affects OCS Inventory NG version 1.02.1.
Exploitation of CVE-2010-1595 can lead to unauthorized access to the database and execution of arbitrary SQL commands.
You can detect vulnerability to CVE-2010-1595 by testing input parameters in OCS Inventory NG 1.02.1 for SQL injection behavior.