7.5
CVSSv2

CVE-2009-4372

Published: 21/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions prior to 2.1.5-4, allows remote malicious users to execute arbitrary commands via shell metacharacters in the uniqueid parameter to (1) wcl.php, (2) storage_graphs.php, (3) storage_graphs2.php, (4) storage_graphs3.php, and (5) storage_graphs4.php in sem/.

Vulnerable Product Search on Vulmon Subscribe to Product

alienvault open source security information management 2.1.5-1

alienvault open source security information management 2.1.5-2

alienvault open source security information management 2.1.5-3

alienvault open source security information management 2.1.5

Exploits

Advisory Name: Remote Command Execution in OSSIM Vulnerability Class: Remote Command Execution Release Date: 12-16-2009 Affected Applications: Confirmed in OSSIM 215 Other versions may also be affected Affected Platforms: Multiple Local / Remote: Remote Severity: High – CVSS: 9 (AV:N/AC:L/Au:S/C:C/I:C/A:C) Researcher: Nahuel Grisolía ...