CVE-2009-3042 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter a different vector than CVE-2009-3040.
Reference
http://seclists.org/fulldisclosure/2009/Aug/0143.html http://secunia.com/advisories/35311 http://www.exploit-db.com/exploits/9416 http://www.ocsinventory-ng.org/index.php?mact=Newscntnt01detail0&cntnt01articleid=147&cntnt01returnid=15 http://www.securityfocus.com/archive/1/505675/100/0/threaded
Share on: