Some vulnerabilities were reported [1],[2] in OCS Inventory NG which could be exploited to conduct SQL injection attacks. Input passwd to the 'systemid' parameter in group_show.php and machine.php is not properly sanitized before being used in an SQL query, which can be used to inject arbitrary SQL code. The vulnerabilities are confirmed in version 1.02.1 (current version in Fedora and EPEL). A patch for machine.php is here: http://ocsinventory.svn.sourceforge.net/viewvc/ocsinventory/branches/server/1.02/ocsreports/machine.php?r1=1762&r2=1829 [1] http://secunia.com/advisories/35311/ [2] http://seclists.org/fulldisclosure/2009/Aug/0143.html
*** This bug has been marked as a duplicate of bug 517837 ***