{"id":"CVE-2010-1595","details":"Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3) onglet_bis parameter.","modified":"2026-04-10T03:41:13.381920Z","published":"2010-04-28T23:30:00Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/38311"},{"type":"ADVISORY","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:178"},{"type":"EVIDENCE","url":"http://packetstormsecurity.org/1001-exploits/ocsinventoryng-sqlxss.txt"},{"type":"WEB","url":"http://osvdb.org/61942"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55872"}],"schema_version":"1.7.5"}