CVE-2009-3040
EPSS 0.14%
Description
Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.
How to fix CVE-2009-3040
To remediate CVE-2009-3040, upgrade the affected package to a fixed version below.
- Debian/ocsinventory-server—upgrade to 1.02.1-2 or later
Is CVE-2009-3040 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.02.1-2