CVE-2009-2166
22.06.2009, 20:30
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
| Vendor | Product | Version |
|---|---|---|
| ocsinventory-ng | ocs_inventory_ng | 𝑥 ≤ 1.02 |
| ocsinventory-ng | ocs_inventory_ng | 1.0 |
| ocsinventory-ng | ocs_inventory_ng | 1.0:beta |
| ocsinventory-ng | ocs_inventory_ng | 1.0:rc1 |
| ocsinventory-ng | ocs_inventory_ng | 1.0:rc2 |
| ocsinventory-ng | ocs_inventory_ng | 1.0:rc3 |
| ocsinventory-ng | ocs_inventory_ng | 1.0:rc3-1 |
| ocsinventory-ng | ocs_inventory_ng | 1.01 |
| ocsinventory-ng | ocs_inventory_ng | 1.02:rc1 |
| ocsinventory-ng | ocs_inventory_ng | 1.02:rc2 |
| ocsinventory-ng | ocs_inventory_ng | 1.02:rc3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ocsinventory-server |
|
References