7.5
CVSSv2

CVE-2009-4375

Published: 21/12/2009 Updated: 11/05/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions prior to 2.1.5-4, allows remote malicious users to execute arbitrary SQL commands via the id_document parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

alienvault open source security information management 2.1.5-2

alienvault open source security information management 2.1.5-1

alienvault open source security information management 2.1.5-3

alienvault open source security information management 2.1.5

Exploits

Advisory Name: SQL injection in OSSIM Vulnerability Class: SQL injection Release Date: 12-16-2009 Affected Applications: Confirmed in OSSIM 215 Other versions may also be affected Affected Platforms: Multiple Local / Remote: Remote Severity: High – CVSS: 9 (AV:N/AC:L/Au:S/C:C/I:C/A:C) Researcher: Nahuel Grisolía Vendor Status: Acknow ...