Back to search
CVE-2009-3042
Published: Sep 1, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
9416
exploit
x_refsource_EXPLOIT-DB
20090811 Sql injection in OCS Inventory NG Server 1.2.1
mailing-list
x_refsource_FULLDISC
20090811 Sql injection in OCS Inventory NG Server 1.2.1
mailing-list
x_refsource_BUGTRAQ
35311
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now