Exploitation Summary
EIP tracks 1 public exploit for CVE-2013-5321. PoCs published by Glafkos Charalambous.
AI-analyzed exploit summary The exploit demonstrates multiple blind SQL injection vulnerabilities in AlienVault OSSIM 4.1. It provides specific URLs with injectable parameters such as 'sensor', 'tcp_flags', and 'sortby' to exploit the vulnerabilities.
Description
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to forensics/base_stat_alerts.php; the (4) ip_addr[1][8] or (5) port_type parameter to forensics/base_stat_ports.php; or the (6) sortby or (7) rvalue parameter in a search action to vulnmeter/index.php.
Exploits (1)
The exploit demonstrates multiple blind SQL injection vulnerabilities in AlienVault OSSIM 4.1. It provides specific URLs with injectable parameters such as 'sensor', 'tcp_flags', and 'sortby' to exploit the vulnerabilities.