peter bassill · operator
$ cve CVE-2009-3040 JSON

CVE-2009-3040 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.4% (pctl 72)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.42% — more likely to be exploited than 72% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2009-09-01
Last modified2026-06-16

Affected (1)

VendorProduct
ocsinventory-ngocs inventory ng

Public exploits

SourceTitleDate
exploit-dbOCS Inventory NG 1.02 - Multiple SQL Injections2009-06-01

References

→ the Explorer  ·  watch your stack  ·  NVD