PT-2018-11211 · Ocs · Ocs Inventory Ng

Juan Manuel Fernandez

·

Published

2018-08-03

·

Updated

2018-10-02

·

CVE-2018-12483

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OCS Inventory version 2.4.1
Description The issue is a remote command-execution problem. It happens because the content of the ipdiscover analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. To exploit this, authentication is required.
Recommendations For OCS Inventory version 2.4.1, consider restricting access to the ipdiscover analyser module to minimize the risk of exploitation. Avoid using the rzo parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12483

Affected Products

Ocs Inventory Ng