Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2018-12482
Disclosure Date: August 04, 2018 (last updated November 27, 2024)
OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.
0
Attacker Value
Unknown
CVE-2018-14473
Disclosure Date: August 04, 2018 (last updated November 27, 2024)
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.
0
Attacker Value
Unknown
CVE-2018-12483
Disclosure Date: August 04, 2018 (last updated November 27, 2024)
OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability.
0