10
CVSSv2

CVE-2014-3805

Published: 13/06/2014 Updated: 16/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The av-centerd SOAP service in AlienVault OSSIM prior to 4.7.0 allows remote malicious users to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alienvault open source security information management

alienvault open source security information management 4.6

alienvault open source security information management 4.1.2

alienvault open source security information management 4.1.3

alienvault open source security information management 4.2

alienvault open source security information management 4.3.3

alienvault open source security information management 4.0.3

alienvault open source security information management 4.3

alienvault open source security information management 4.3.1

alienvault open source security information management 4.0

alienvault open source security information management 4.0.4

alienvault open source security information management 4.1

alienvault open source security information management 4.3.2

alienvault open source security information management 4.5

alienvault open source security information management 4.4

alienvault open source security information management 4.2.2

alienvault open source security information management 4.2.3

Exploits

require 'msf/core' require 'rexml/document' class MetasploitModule < Msf::Exploit::Remote Rank = ExcellentRanking include Msf::Exploit::Remote::HttpClient include REXML def initialize(info = {}) super(update_info(info, 'Name' => 'Alienvault OSSIM av-centerd Command Injection get_log_line', 'Description' => %q{ This modu ...
# Exploit Title: AlienVault OSSIM < 470 av-centerd 'get_log_line()' Remote Code Execution # Date: 06/17/2014 # Exploit Author: Alfredo Ramirez # Vendor Homepage: wwwalienvaultcom/ # Software Link: wwwalienvaultcom/open-threat-exchange/projects # Version: < 470 # Tested on: Debian/Virtual Appliance # CVE : CVE-2014-3805 ...