Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2009-2166
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.019
EPSS Ranking
82.3%
CVSS Severity
CVSS v2 Score
5.0
References
http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_directory_traversal.shtml
http://www.securityfocus.com/archive/1/504047/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/50946
https://www.exploit-db.com/exploits/8868
http://www.leidecker.info/advisories/2009-05-30-ocs_inventory_ng_directory_traversal.shtml
http://www.securityfocus.com/archive/1/504047/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/50946
https://www.exploit-db.com/exploits/8868
Products affected by CVE-2009-2166
Ocsinventory-Ng
»
Ocs Inventory Ng
»
Version:
Any
cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:*
Ocsinventory-Ng
»
Ocs Inventory Ng
»
Version:
1.0
cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.0
Ocsinventory-Ng
»
Ocs Inventory Ng
»
Version:
1.01
cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.01
Ocsinventory-Ng
»
Ocs Inventory Ng
»
Version:
1.02
cpe:2.3:a:ocsinventory-ng:ocs_inventory_ng:1.02
Unix
»
Unix
»
Version:
Any
cpe:2.3:o:unix:unix:*
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved