NA

CVE-2012-2599

Published: 20/02/2020 Updated: 07/11/2023

Vulnerability Summary

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-3835. Reason: This issue was MERGED into CVE-2012-3835 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2012-3835 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

Vulnerability Trend

Exploits

##################################################################################### # Advisory: Alienvault OSSIM Open Source SIEM 31 Multiple security vulnerabilities # Advisory ID: SSCHADV-EDB-2012-001 # Contact: sschurtz@darksecurityde # Author: Stefan Schurtz # Affected Software: Successfully tested on Alienvault Open Source SIEM 31 (32bit) ...
#!/usr/bin/python ''' AlienVault has a reflected XSS vulnerability in the "url" parameter of "topphp" Proof of Concept: Enticing a logged in user to visit the following URL where an attacker is hosting an cookie grabber will allow for the hijacking of the user session: victim/ossim/topphp?option=3&soption=3&url=<script sr ...