CVE-2009-2166
22.06.2009, 20:30
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
Vendor | Product | Version |
---|---|---|
ocsinventory-ng | ocs_inventory_ng | 𝑥 ≤ 1.02 |
ocsinventory-ng | ocs_inventory_ng | 1.0 |
ocsinventory-ng | ocs_inventory_ng | 1.0:beta |
ocsinventory-ng | ocs_inventory_ng | 1.0:rc1 |
ocsinventory-ng | ocs_inventory_ng | 1.0:rc2 |
ocsinventory-ng | ocs_inventory_ng | 1.0:rc3 |
ocsinventory-ng | ocs_inventory_ng | 1.0:rc3-1 |
ocsinventory-ng | ocs_inventory_ng | 1.01 |
ocsinventory-ng | ocs_inventory_ng | 1.02:rc1 |
ocsinventory-ng | ocs_inventory_ng | 1.02:rc2 |
ocsinventory-ng | ocs_inventory_ng | 1.02:rc3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ocsinventory-server |
|
References