← Vulnerability feed

Vulnerability record · CVE-2010-1595 · published 28 April 2010

CVE-2010-1595: Ocsinventory-ng ocs inventory ng sql injection vulnerability

Ocsinventory Ng · Ocs Inventory Ng

Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3) onglet_bis parameter.

7.5 CVSS 2.0 High EPSS 1.2% · top 33.1% CWE-89 · SQL injection
7.5CVSS 2.0 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3) onglet_bis parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-1595 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1443Ocsinventory-ng ocs inventory ng vulnerabilityMultiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.EPSS 4.0%7.5CVE-2009-3042Ocsinventory-ng ocs inventory ng sql injection vulnerabilitySQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL c…EPSS 3.0%7.5CVE-2009-3040Ocsinventory-ng ocs inventory ng sql injection vulnerabilityMultiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL…EPSS 1.4%7.2CVE-2009-0667Ocsinventory-ng ocs inventory ng vulnerabilityUntrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local use…EPSS 0.37%6.8CVE-2010-1733Ocsinventory-ng ocs inventory ng sql injection vulnerabilityMultiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple in…EPSS 1.0%5.0CVE-2009-2166Ocsinventory-ng ocs inventory ng path traversal vulnerabilityAbsolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full…EPSS 3.2%5.0CVE-2009-1769Ocsinventory-ng ocs inventory ng information exposure vulnerabilityThe web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whe…EPSS 1.6%4.3CVE-2011-4024Ocsinventory-ng ocs inventory ng cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script…EPSS 5.1%

Source: NIST National Vulnerability Database (record CVE-2010-1595), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.