OCS Inventory NG Cross Site Scripting and SQL Injection Vulnerabilities
BID:43177
Info
OCS Inventory NG Cross Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 43177 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1594 CVE-2010-1595 CVE-2010-1733 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2010 12:00AM |
| Updated: | Mar 19 2015 08:28AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Ocsinventory-Ng OCS Inventory NG Server 1.2.2 Ocsinventory-Ng OCS Inventory NG Server 1.2.1 Ocsinventory-Ng OCS Inventory NG Server 1.02 Ocsinventory-Ng OCS Inventory NG Server 1.01 Ocsinventory-Ng OCS Inventory NG Server 1.00 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 |
| Not Vulnerable: |
Ocsinventory-Ng OCS Inventory NG Server 1.2.3 |
Discussion
OCS Inventory NG Cross Site Scripting and SQL Injection Vulnerabilities
OCS Inventory NG is prone to multiple SQL-injection vulnerabilities and a cross-site scripting vulnerability.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
OCS Inventory NG 1.02.2 and prior are vulnerable; other versions may also be affected.
OCS Inventory NG is prone to multiple SQL-injection vulnerabilities and a cross-site scripting vulnerability.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
OCS Inventory NG 1.02.2 and prior are vulnerable; other versions may also be affected.
Exploit / POC
OCS Inventory NG Cross Site Scripting and SQL Injection Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
OCS Inventory NG Cross Site Scripting and SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva ocsinventory-reports-1.02.3-0.1mdvmes5.1.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva ocsinventory-server-1.02.3-0.1mdvmes5.1.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva ocsinventory-reports-1.02.3-0.1mdvmes5.1.noarch.rpm
http://www.mandriva.com/en/download/ -
Mandriva ocsinventory-server-1.02.3-0.1mdvmes5.1.noarch.rpm
http://www.mandriva.com/en/download/
References
OCS Inventory NG Cross Site Scripting and SQL Injection Vulnerabilities
References:
References:
- Mandriva Security Advisory MDVSA-2010:178 (Mandriva)
- OCS Inventory NG Homepage (OCS Inventory Team)
- OCS Inventory NG Server 1.02.3 (OCS Inventory Team)