Bug 519497 - ocsinventory: 'systemid' SQL injection vulnerabilities
Summary: ocsinventory: 'systemid' SQL injection vulnerabilities
Keywords:
Status: CLOSED DUPLICATE of bug 517837
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 519498
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-08-26 20:58 UTC by Vincent Danen
Modified: 2019-09-29 12:31 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2009-08-27 15:02:50 UTC
Embargoed:


Attachments (Terms of Use)

Description Vincent Danen 2009-08-26 20:58:09 UTC
Some vulnerabilities were reported [1],[2] in OCS Inventory NG which could be exploited to conduct SQL injection attacks.  Input passwd to the 'systemid' parameter in group_show.php and machine.php is not properly sanitized before being used in an SQL query, which can be used to inject arbitrary SQL code.  The vulnerabilities are confirmed in version 1.02.1 (current version in Fedora and EPEL).

A patch for machine.php is here:  http://ocsinventory.svn.sourceforge.net/viewvc/ocsinventory/branches/server/1.02/ocsreports/machine.php?r1=1762&r2=1829

[1] http://secunia.com/advisories/35311/
[2] http://seclists.org/fulldisclosure/2009/Aug/0143.html

Comment 2 Vincent Danen 2009-08-27 15:02:50 UTC

*** This bug has been marked as a duplicate of bug 517837 ***


Note You need to log in before you can comment on or make changes to this bug.