vendor:
OSSIM/USM
by:
Peter Lapp
8.8
CVSS
HIGH
XSS, SQLi, Command Execution
79, 89, 78
CWE
Product Name: OSSIM/USM
Affected Version From: 4.14
Affected Version To: 5
Patch Exists: NO
Related CWE: None assigned
CPE: a:alienvault:ossim
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Multiple Vulnerabilities in Alienvault OSSIM/USM
Using a specially crafted NBE file, a user can exploit multiple vulnerabilities such as XSS, SQLi, and Command Execution. Authentication is required to exploit this vulnerability, but admin privileges are not required. Any user with access to the Vulnerabilities page can perform these attacks.
Mitigation:
No fix has been released.