vendor:
OSSIM
by:
Glafkos Charalambous
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: OSSIM
Affected Version From: 4.1
Affected Version To: 4.1
Patch Exists: YES
Related CWE: N/A
CPE: a:alienvault:ossim:4.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Alienvault OSSIM Open Source SIEM 4.1 Multiple SQL Vulnerabilities
Multiple Blind SQL Injection vulnerabilities were detected in the Alienvault OSSIM Open Source SIEM 4.1 product. An example POC was provided, which included a GET parameter injection in the sensor, tcp_flags, and tcp_port fields.
Mitigation:
AlienVault has released a patch to address this vulnerability.