6.5
CVSSv2

CVE-2014-5383

Published: 21/08/2014 Updated: 08/09/2015
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in AlienVault OSSIM prior to 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

alienvault open source security information management 4.3

alienvault open source security information management 4.2.3

alienvault open source security information management 4.2.2

alienvault open source security information management 4.2

alienvault open source security information management 2.1.5

alienvault open source security information management 2.1.2

alienvault open source security information management 2.1

alienvault open source security information management 1.0.6

alienvault open source security information management

alienvault open source security information management 4.6

alienvault open source security information management 4.5

alienvault open source security information management 4.0.3

alienvault open source security information management 4.0

alienvault open source security information management 3.1.9

alienvault open source security information management 3.1.12

alienvault open source security information management 3.1.10

alienvault open source security information management 4.4

alienvault open source security information management 4.3.2

alienvault open source security information management 4.1.2

alienvault open source security information management 4.0.4

alienvault open source security information management 2.1.5-3

alienvault open source security information management 2.1.5-1

alienvault open source security information management 1.0.4

alienvault open source security information management 4.3.3

alienvault open source security information management 4.3.1

alienvault open source security information management 4.1.3

alienvault open source security information management 4.1

alienvault open source security information management 3.1

alienvault open source security information management 2.1.5-2

Exploits

Exploit Title: AlienVault newpolicyformphp SQLi Date: 5/9/2014 Exploit Author: chrisdhebert[at]gmailcom Vendor Homepage: wwwalienvaultcom/ Software Link: wwwalienvaultcom/free-downloads-services Version: 461 and below Tested on: Linux CVE : n/a Vendor Security Advisory : AV-11394 forumsalienvaultcom/discussion/2690/se ...