CVE-2009-3040 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 1.4% (pctl 72)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.42% — more likely to be exploited than 72% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-09-01 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ocsinventory-ng | ocs inventory ng |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | OCS Inventory NG 1.02 - Multiple SQL Injections | 2009-06-01 |
References
- http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_sql_injection.shtml
- http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=140&cntnt01returnid=72
- http://www.securityfocus.com/archive/1/503936/100/0/threaded
- http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_sql_injection.shtml
- http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=140&cntnt01returnid=72
- http://www.securityfocus.com/archive/1/503936/100/0/threaded
→ the Explorer · watch your stack · NVD