7.5
CVSSv2

CVE-2013-5967

Published: 09/10/2013 Updated: 10/10/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and previous versions allow remote malicious users to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3) radar-iso27001-A11AccessControl-pot.php, (4) radar-iso27001-A10Com_OP_Mgnt-pot.php, or (5) radar-pci-potential.php in RadarReport/.

Vulnerable Product Search on Vulmon Subscribe to Product

alienvault open source security information management 4.0.4

alienvault open source security information management 4.0.3

alienvault open source security information management 3.1.9

alienvault open source security information management 3.1.12

alienvault open source security information management 3.1.10

alienvault open source security information management 4.2.3

alienvault open source security information management 4.2.2

alienvault open source security information management 2.1.5

alienvault open source security information management 2.1.2

alienvault open source security information management 2.1

alienvault open source security information management 1.0.6

alienvault open source security information management 4.1.3

alienvault open source security information management 4.1

alienvault open source security information management 2.1.5-3

alienvault open source security information management 2.1.5-1

alienvault open source security information management 1.0.4

alienvault open source security information management 4.2

alienvault open source security information management 4.1.2

alienvault open source security information management 3.1

alienvault open source security information management 2.1.5-2

alienvault open source security information management

Exploits

source: wwwsecurityfocuscom/bid/62790/info Open Source SIEM (OSSIM) is prone to multiple SQL-injection vulnerabilities A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database Open Source SIEM (OSSIM) 430 and prior are vulnerable ...