CVE-2013-5321

AlienVault OSSIM 4.1 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to forensics/base_stat_alerts.php; the (4) ip_addr[1][8] or (5) port_type parameter to forensics/base_stat_ports.php; or the (6) sortby or (7) rvalue parameter in a search action to vulnmeter/index.php.

Exploits (1)

exploitdb WORKING POC
by Glafkos Charalambous · textwebappsphp
https://www.exploit-db.com/exploits/26406

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/26406

Scores

EPSS 0.0078
EPSS Percentile 73.7%

Details

CWE
CWE-89
Status published
Products (1)
alienvault/open_source_security_information_management 4.1
Published Aug 20, 2013
Tracked Since Feb 18, 2026