CVE-2009-1443

OCS Inventory NG <1.02 - Unspecified Vuln

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1443. PoCs published by Nicolas DEROUET.

AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in OCS Inventory NG Server's login mechanism to bypass authentication. It constructs a malicious SQL query via the login field, allowing an attacker to log in as any user, including administrators, without valid credentials.

Description

Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.

Exploits (1)

exploitdb WORKING POC
by Nicolas DEROUET · htmlwebappsphp
https://www.exploit-db.com/exploits/12520

This exploit leverages a SQL injection vulnerability in OCS Inventory NG Server's login mechanism to bypass authentication. It constructs a malicious SQL query via the login field, allowing an attacker to log in as any user, including administrators, without valid credentials.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: OCS Inventory NG Server <= 1.3.1 (except 1.02.1 to 1.02.3)
No auth needed
Prerequisites: Access to the OCS Inventory NG login page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1152
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34763
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34694

Scores

EPSS 0.0401
EPSS Percentile 89.2%

Details

Status published
Products (2)
ocsinventory-ng/ocs_inventory_ng 1.0 (6 CPE variants)
ocsinventory-ng/ocs_inventory_ng < 1.01
Published Apr 27, 2009
Tracked Since Feb 18, 2026