Skip to main content

Vendor/product archive

ocsinventory-ng / ocs_inventory_ng CVEs

Beta · best-effort

10 CVEs tagged to ocsinventory-ng / ocs_inventory_ng1 Critical, 4 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2011-4024

Published Oct 21, 2011

Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1733

Published May 6, 2010

Multiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search f…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1595

Published Apr 28, 2010

Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-1594

Published Apr 28, 2010

Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the qu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3042

Published Sep 1, 2009

SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid param…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3040

Published Sep 1, 2009

Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) D…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2166

Published Jun 22, 2009

Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1769

Published May 22, 2009

The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whether a username is valid, whic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1443

Published Apr 27, 2009

Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1