debian · CVE-2009-3040

Quick triage

Priority: unimportant Published: Updated: Thu, 11 Jun 2026 23:58:15 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2009-3040 unimportant priority: Debian including 1 source packages (ocsinventory-server), 3 status rows across 3 suites (bookworm, bullseye, sid): resolved 3.

Description:

Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.

cvelogic Threat Intelligence