{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"OCS Inventory NG Server versions ant\u00e9rieures \u00e0 1.02.1 sur GNU Linux/UNIX;","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"OCS Inventory NG Server versions ant\u00e9rieures \u00e0 1.02.1 sur Microsoft Windows.","product":{"name":"Windows","vendor":{"name":"Microsoft","scada":false}}}],"affected_systems_content":null,"content":"## Description\n\nDeux failles ont \u00e9t\u00e9 corrig\u00e9es dans OCS Inventory NG Server. La premi\u00e8re\npermet \u00e0 une personne malintentionn\u00e9e d'effectuer des injections SQL. La\nseconde vuln\u00e9rabilit\u00e9 (CVE-2009-2261), dans le fichier cvs.php, permet \u00e0\nune personne d'acc\u00e9der \u00e0 des fichiers arbitraires du syst\u00e8me.\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2009-2261","url":"https://www.cve.org/CVERecord?id=CVE-2009-2261"},{"name":"CVE-2009-2166","url":"https://www.cve.org/CVERecord?id=CVE-2009-2166"}],"links":[],"reference":"CERTA-2009-AVI-250","revisions":[{"description":"version initiale.","revision_date":"2009-06-24T00:00:00.000000"}],"risks":[{"description":"Injection SQL"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 corrig\u00e9es dans OCS Inventory NG\nServer.\n","title":"Vuln\u00e9rabilit\u00e9s dans OCS Inventory NG Server","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 OCS Inventory du 30 mai 2009","url":"http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&cntnt01articleid=140&cntnt01returnid=111"}]}
