CVE-2010-1594
published 2010-04-28CVE-2010-1594: Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or…
PriorityP414medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.13%
62.4th percentile
Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these details are obtained from third party information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ocsinventory-server | < ocsinventory-server 1.02.1-1 (bookworm) | ocsinventory-server 1.02.1-1 (bookworm) |
| ocsinventory-ng | ocs_inventory_ng | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-1594: ocsinventory-server - Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in O...
vendor_debian·2010·CVSS 4.3
CVE-2010-1594 [MEDIUM] CVE-2010-1594: ocsinventory-server - Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in O...
Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 1.02.1-1)
bullseye: resolved (fixed in 1.02.1-1)
sid: resolved (fixed in 1.02.1-1)
GHSA
GHSA-88m7-jg48-r9mg: Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index
ghsa_unreviewed·2022-05-17
CVE-2010-1594 [MEDIUM] CWE-79 GHSA-88m7-jg48-r9mg: Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index
Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these details are obtained from third party information.
OSV
CVE-2010-1594: Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index
osv·2010-04-28·CVSS 4.3
CVE-2010-1594 [MEDIUM] CVE-2010-1594: Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index
Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter. NOTE: some of these details are obtained from third party information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/61943http://packetstormsecurity.org/1001-exploits/ocsinventoryng-sqlxss.txthttp://secunia.com/advisories/38311http://www.mandriva.com/security/advisories?name=MDVSA-2010:178https://exchange.xforce.ibmcloud.com/vulnerabilities/55874http://osvdb.org/61943http://packetstormsecurity.org/1001-exploits/ocsinventoryng-sqlxss.txthttp://secunia.com/advisories/38311http://www.mandriva.com/security/advisories?name=MDVSA-2010:178https://exchange.xforce.ibmcloud.com/vulnerabilities/55874
2010-04-28
Published