CVE-2010-4186

Onlinetechtools.com Oasys Professional - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: some of these details are obtained from third party information.

Exploits (2)

exploitdb WRITEUP VERIFIED
by VSN · textwebappsphp
https://www.exploit-db.com/exploits/34951
exploitdb WRITEUP VERIFIED
by L0rd CrusAd3r · textwebappsasp
https://www.exploit-db.com/exploits/15397

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42111
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44608
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/62972
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/68972
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15397

Scores

EPSS 0.0037
EPSS Percentile 58.8%

Details

CWE
CWE-89
Status published
Products (1)
onlinetechtools.com/oasys_professional 2.10
Published Nov 05, 2010
Tracked Since Feb 18, 2026