7.8
CVSSv2

CVE-2014-4153

Published: 18/06/2014 Updated: 19/06/2014
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The av-centerd SOAP service in AlienVault OSSIM prior to 4.8.0 allows remote malicious users to read arbitrary files via a crafted get_file request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alienvault open source security information management 4.6

alienvault open source security information management 4.5

alienvault open source security information management 4.4

alienvault open source security information management 4.3.3

alienvault open source security information management 4.0

alienvault open source security information management

alienvault open source security information management 4.6.1

Exploits

require 'msf/core' class MetasploitModule < Msf::Auxiliary include Msf::Exploit::Remote::HttpClient def initialize super( 'Name' => 'Alienvault OSSIM av-centerd Utilpm get_file Information Disclosure', 'Description' => %q{ This module exploits an information disclosure vulnerability found within the get_file fu ...