在 端点的 参数中存在 SQL 注入漏洞。具有操作员权限的已认证用户提供的输入未经验证或未进行适当的参数化处理,便被直接拼接到 SQL 查询语句中,攻击者可利用 SQL 注入技术操纵该查询,从而从数据库中提取信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OCS Inventory NG | Ocsreports | 2.12.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OCS Inventory NG | Ocsreports | 2.12.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76174 | 9.4 CRITICAL | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76178 | 9.2 CRITICAL | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76176 | 8.6 HIGH | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-76177 | 7.1 HIGH | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
No comments yet