CVE-2009-3042
ocs_inventory_ng 1.02.1 - SQL Injection via machine.php systemid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3042. PoCs published by Guilherme Marinheiro.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in OCS Inventory NG Server 1.2.1, allowing an authenticated attacker to extract sensitive information such as user credentials and database version via a crafted UNION-based SQL query.
Description
SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in OCS Inventory NG Server 1.2.1, allowing an authenticated attacker to extract sensitive information such as user credentials and database version via a crafted UNION-based SQL query.