← Vulnerability feed

Vulnerability record · CVE-2011-4024 · published 21 October 2011

CVE-2011-4024: Ocsinventory-ng ocs inventory ng cross-site scripting vulnerability

Ocsinventory Ng · Ocs Inventory Ng

Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4.3 CVSS 2.0 Medium EPSS 5.1% · top 7.9% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4024 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1443Ocsinventory-ng ocs inventory ng vulnerabilityMultiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.EPSS 4.0%7.5CVE-2010-1595Ocsinventory-ng ocs inventory ng sql injection vulnerabilityMultiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands vi…EPSS 1.2%7.5CVE-2009-3042Ocsinventory-ng ocs inventory ng sql injection vulnerabilitySQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL c…EPSS 3.0%7.5CVE-2009-3040Ocsinventory-ng ocs inventory ng sql injection vulnerabilityMultiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL…EPSS 1.4%7.2CVE-2009-0667Ocsinventory-ng ocs inventory ng vulnerabilityUntrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local use…EPSS 0.37%6.8CVE-2010-1733Ocsinventory-ng ocs inventory ng sql injection vulnerabilityMultiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple in…EPSS 1.0%5.0CVE-2009-2166Ocsinventory-ng ocs inventory ng path traversal vulnerabilityAbsolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full…EPSS 3.2%5.0CVE-2009-1769Ocsinventory-ng ocs inventory ng information exposure vulnerabilityThe web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whe…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2011-4024), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.