VYPR

Ocsinventory Ng

by Ocsinventory Ng

CVEs (23)

  • CVE-2010-1594Apr 28, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these details are…

  • CVE-2009-0667Jul 9, 2009
    risk 0.00cvss —epss 0.00

    Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.

  • CVE-2009-1769May 22, 2009
    risk 0.00cvss —epss 0.02

    The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whether a username is valid, which allows remote attackers to enumerate valid usernames.

Page 2 of 2