CVE-2010-1733: SQL Injection
Multiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search form, reachable through index.php; or (2) the "Software name" field to the "All softwares" search form, reachable through index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1733?
CVE-2010-1733 is classified as a medium severity vulnerability due to its capability to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2010-1733?
To fix CVE-2010-1733, upgrade OCS Inventory NG to version 1.02.3 or later, which addresses these SQL injection vulnerabilities.
What are the affected versions for CVE-2010-1733?
The affected versions for CVE-2010-1733 include OCS Inventory NG versions up to 1.02.1, as well as beta and release candidate versions up to 1.0-rc3.
What types of attacks can CVE-2010-1733 facilitate?
CVE-2010-1733 can facilitate SQL injection attacks, potentially allowing attackers to manipulate the database and execute arbitrary SQL commands.
Is CVE-2010-1733 easy to exploit?
CVE-2010-1733 is relatively easy to exploit, as it involves simple input manipulation in the search fields of OCS Inventory NG.