Tuesday, September 14, 2010

ocsinventory: Multiple SQL-injection Vulnerabilities

Users of ocsinventory please be advised of a Multiple SQL-injection Vulnerabilities that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
MDVSA-2010:178: [MDVSA-2010:178] ocsinventory Multiple SQL-injection Vulnerabilities
Problem Description:



Multiple vulnerabilities has been found and corrected in ocsinventory:



Multiple cross-site scripting (XSS) vulnerabilities in

ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers

to inject arbitrary web script or HTML via (1) the query string, (2)

the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these

details are obtained from third party information (CVE-2010-1594).
Read more at www.criticalwatch.com
 

No comments:

Post a Comment