CVE-2010-1733

NameCVE-2010-1733
DescriptionMultiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search form, reachable through index.php; or (2) the "Software name" field to the "All softwares" search form, reachable through index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ocsinventory-server (PTS)jessie2.0.5-1.3fixed
buster (security), buster, buster (lts)2.5+dfsg1-1+deb10u1fixed
bullseye2.8.1+dfsg1-1+deb11u1fixed
sid, trixie, bookworm2.8.1+dfsg1+~2.11.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ocsinventory-serversource(unstable)2.0-1unimportant

Notes

Authentication is needed, only supported in trusted environments, see debtags

Search for package or bug name: Reporting problems