|
Brought to you by:
Suppliers of:
|
|
|
| |
| The Open Computer and Software (OCS) Inventory Next Generation (NG) provides relevant inventory information about system configurations and software on the network. The server can be managed using a web interface. This application does not properly sanitize user input which results into multiple SQL injections. |
| |
Credit:
The information has been provided by nico at leidecker.info.
The original article can be found at: http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_sql_injection.shtml
|
| |
Vulnerable Systems:
* OCS Inventory NG version 1.02
The following scripts are affected:
* download.php (parameters `N', `DL', `O' and `V')
* group_show.php (parameter `SYSTEMID');
Attackers may be able to manipulate SQL statements in such a way that they can retrieve, create or modify information stored in the database. Furthermore, the SQL injection might allow attackers to get a foothold on the underlying system.
Vendor Status:
Vendor has been notified and the vulnerability has been fixed.
|
|
|
|
|