CVE-2010-1733

Multiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search form, reachable through index.php; or (2) the "Software name" field to the "All softwares" search form, reachable through index.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
VendorProductVersion
ocsinventory-ngocs_inventory_ng
𝑥
≤ 1.02.1
ocsinventory-ngocs_inventory_ng
1.0:beta
ocsinventory-ngocs_inventory_ng
1.0:rc1
ocsinventory-ngocs_inventory_ng
1.0:rc2
ocsinventory-ngocs_inventory_ng
1.0:rc3
ocsinventory-ngocs_inventory_ng
1.0:rc3-1
ocsinventory-ngocs_inventory_ng
1.01
ocsinventory-ngocs_inventory_ng
1.02
ocsinventory-ngocs_inventory_ng
1.02
ocsinventory-ngocs_inventory_ng
1.02:rc1
ocsinventory-ngocs_inventory_ng
1.02:rc2
ocsinventory-ngocs_inventory_ng
1.02:rc3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ocsinventory-server
bullseye
2.8.1+dfsg1-1+deb11u1
fixed
sid
2.8.1+dfsg1+~2.11.1-1
fixed
trixie
2.8.1+dfsg1+~2.11.1-1
fixed
bookworm
2.8.1+dfsg1+~2.11.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ocsinventory-server
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
ignored
maverick
ignored
lucid
ignored
karmic
ignored
jaunty
ignored
hardy
ignored
dapper
dne