VendorsOCSInventory-NGocsinventory_ng2.4.1
Vulnerabilities

OCSInventory-NG Ocsinventory Ng 2.4.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-14473
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.
Published 2018-08-03 · Modified
9.1EPSS 0.031
CVE-2018-12483
OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability.
Published 2018-08-03 · Modified
9.0EPSS 0.032
CVE-2018-12482
OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.
Published 2018-08-03 · Modified
8.8EPSS 0.013