10
CVSSv2

CVE-2014-5210

Published: 21/08/2014 Updated: 21/08/2014
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The av-centerd SOAP service in AlienVault OSSIM prior to 4.7.0 allows remote malicious users to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alienvault open source security information management

alienvault open source security information management 4.5

alienvault open source security information management 4.3

alienvault open source security information management 4.2.2

alienvault open source security information management 4.0

alienvault open source security information management 3.1.12

alienvault open source security information management 2.1.2

alienvault open source security information management 1.0.6

alienvault open source security information management 4.1.3

alienvault open source security information management 4.1.2

alienvault open source security information management 4.1

alienvault open source security information management 4.0.4

alienvault open source security information management 4.0.3

alienvault open source security information management 1.0.4

alienvault open source security information management 4.4

alienvault open source security information management 4.3.3

alienvault open source security information management 4.3.2

alienvault open source security information management 4.3.1

alienvault open source security information management 3.1

alienvault open source security information management 2.1.5-3

alienvault open source security information management 2.1.5-2

alienvault open source security information management 2.1.5-1

alienvault open source security information management 4.6

alienvault open source security information management 4.2.3

alienvault open source security information management 4.2

alienvault open source security information management 3.1.9

alienvault open source security information management 3.1.10

alienvault open source security information management 2.1.5

alienvault open source security information management 2.1

Exploits

require 'msf/core' require 'rexml/document' class MetasploitModule < Msf::Exploit::Remote Rank = ExcellentRanking include Msf::Exploit::Remote::HttpClient include REXML def initialize(info = {}) super(update_info(info, 'Name' => 'Alienvault OSSIM av-centerd Command Injection get_license', 'Description' => %q{ This modul ...