vendor:
OSSIM/USM
by:
Peter Lapp
9,8
CVSS
CRITICAL
PHP Object Injection
502
CWE
Product Name: OSSIM/USM
Affected Version From: <=5.3.1
Affected Version To: 5.3.2
Patch Exists: YES
Related CWE: CVE-2016-8580
CPE: alienvault:ossim/usm
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
PHP Object Injection
A PHP object injection vulnerability exists in multiple widget files due to the unsafe use of the unserialize() function. The affected files include flow_chart.php, gauge.php, honeypot.php, image.php,inventory.php, otx.php, rss.php, security.php, siem.php, taxonomy.php, tickets.php, and url.php. An authenticated attacker could send a serialized PHP object to one of the vulnerable pages and potentially gain code execution via magic methods in included classes.
Mitigation:
Upgrade to version 5.3.2