// For flags

CVE-2009-2166

OCS Inventory NG 1.02 - Remote File Disclosure

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.

Vulnerabilidad de salto de directorio absoluto en cvs.php en OCS Inventory NG versiones anteriores a v1.02.1 para Unix permite a atacantes remotos leer ficheros de su elección indicando la ruta de directorio completa en el parámetro "log".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-06-22 CVE Reserved
  • 2009-06-22 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
<= 1.02
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version " <= 1.02"
-
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
1.0
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version "1.0"
-
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
1.0
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version "1.0"
beta
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
1.0
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version "1.0"
rc1
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
1.0
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version "1.0"
rc2
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
1.0
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version "1.0"
rc3
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
1.0
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version "1.0"
rc3-1
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
1.01
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version "1.01"
-
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
1.02
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version "1.02"
rc1
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
1.02
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version "1.02"
rc2
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe
Ocsinventory-ng
Search vendor "Ocsinventory-ng"
Ocs Inventory Ng
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng"
1.02
Search vendor "Ocsinventory-ng" for product "Ocs Inventory Ng" and version "1.02"
rc3
Affected
in Unix
Search vendor "Unix"
Unix
Search vendor "Unix" for product "Unix"
*-
Safe