CVE-2010-4186
Last modified
CVE-2010-4186 is a vulnerability of currently unknown severity. SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: some of these details are obtained from third party information.. EPSS estimates a 1.03% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: some of these details are obtained from third party information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Onlinetechtools.Com | Oasys Professional | 2.10 |
References
- http://secunia.com/advisories/42111Vendor Advisory
- http://secunia.com/advisories/42111Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4186?
How severe is CVE-2010-4186?
How do I fix CVE-2010-4186?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-4180OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_…
- CVE-2010-4181Directory traversal vulnerability in Yaws 1.89 allows remote…
- CVE-2010-4182Untrusted search path vulnerability in the Data Access Objec…
- CVE-2010-4183Multiple cross-site scripting (XSS) vulnerabilities in HTML …
- CVE-2010-4184NetSupport Manager (NSM) before 11.00.0005 sends HTTP header…
- CVE-2010-4185SQL injection vulnerability in index.php in Energine, possib…
- CVE-2010-4187Adobe Shockwave Player before 11.5.9.620 allows attackers to…
- CVE-2010-4188The dirapi.dll module in Adobe Shockwave Player before 11.5.…
- CVE-2010-4189The IML32 module in Adobe Shockwave Player before 11.5.9.620…
- CVE-2010-4190Adobe Shockwave Player before 11.5.9.620 allows attackers to…
- CVE-2010-4191Adobe Shockwave Player before 11.5.9.620 allows attackers to…
- CVE-2010-4192Adobe Shockwave Player before 11.5.9.620 allows attackers to…
Are you affected by CVE-2010-4186?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
