Show filters
294 Total Results
Displaying 281-290 of 294
Sort by:
Attacker Value
Unknown

CVE-2009-3042

Disclosure Date: September 01, 2009 (last updated October 04, 2023)
SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.
0
Attacker Value
Unknown

CVE-2009-0667

Disclosure Date: July 09, 2009 (last updated October 04, 2023)
Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.
0
Attacker Value
Unknown

CVE-2009-2166

Disclosure Date: June 22, 2009 (last updated October 04, 2023)
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
0
Attacker Value
Unknown

CVE-2009-1419

Disclosure Date: June 08, 2009 (last updated October 04, 2023)
Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.0.0 through 2.52, 7.50, and 7.51 on Windows allows remote attackers to access DDMI agents via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-1769

Disclosure Date: May 22, 2009 (last updated October 04, 2023)
The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whether a username is valid, which allows remote attackers to enumerate valid usernames.
0
Attacker Value
Unknown

CVE-2009-1443

Disclosure Date: April 27, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2007-4744

Disclosure Date: September 06, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PREFIX parameter.
0
Attacker Value
Unknown

CVE-2007-3270

Disclosure Date: June 19, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the strIncludePrefix parameter.
0
Attacker Value
Unknown

CVE-2007-2343

Disclosure Date: April 27, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.
0
Attacker Value
Unknown

CVE-2007-2344

Disclosure Date: April 27, 2007 (last updated October 04, 2023)
The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field.
0