CVE-2010-1595
EPSS 0.46%
Description
Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3) onglet_bis parameter.
How to fix CVE-2010-1595
To remediate CVE-2010-1595, upgrade the affected package to a fixed version below.
- Debian/ocsinventory-server—upgrade to 1.02.1-1 or later
Is CVE-2010-1595 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.02.1-1