Search CVE reports


Toggle filters

11 – 20 of 24 results


CVE-2018-14857

Medium priority
Not affected

Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template...

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected
Show less packages

CVE-2018-14473

Medium priority
Vulnerable

OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not in release Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-12483

Medium priority
Vulnerable

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the...

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not in release Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-12482

Medium priority
Vulnerable

OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not in release Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-1000558

Negligible priority
Needs evaluation

OCS Inventory NG ocsreports 2.4 and ocsreports 2.3.1 version 2.4 and 2.3.1 contains a SQL Injection vulnerability in web search that can result in An authenticated attacker is able to gain full access to data stored...

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not in release Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-1000557

Negligible priority
Needs evaluation

OCS Inventory OCS Inventory NG version ocsreports 2.4 contains a Cross Site Scripting (XSS) vulnerability in login form and search functionality that can result in An attacker is able to execute arbitrary (javascript) code within...

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not in release Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2014-4722

Medium priority
Vulnerable

Multiple cross-site scripting (XSS) vulnerabilities in the OCS Reports Web Interface in OCS Inventory NG allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not in release Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2011-4024

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server
Show less packages

CVE-2010-1733

Medium priority
Ignored

Multiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search form, reachable through index.php; or (2) the...

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server
Show less packages

CVE-2009-3042

Medium priority
Ignored

SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not affected
Show less packages