CVE-2013-5321

AlienVault OSSIM 4.1 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-5321. PoCs published by Glafkos Charalambous.

AI-analyzed exploit summary The exploit demonstrates multiple blind SQL injection vulnerabilities in AlienVault OSSIM 4.1. It provides specific URLs with injectable parameters such as 'sensor', 'tcp_flags', and 'sortby' to exploit the vulnerabilities.

Description

Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to forensics/base_stat_alerts.php; the (4) ip_addr[1][8] or (5) port_type parameter to forensics/base_stat_ports.php; or the (6) sortby or (7) rvalue parameter in a search action to vulnmeter/index.php.

Exploits (1)

exploitdb WORKING POC
by Glafkos Charalambous · textwebappsphp
https://www.exploit-db.com/exploits/26406

The exploit demonstrates multiple blind SQL injection vulnerabilities in AlienVault OSSIM 4.1. It provides specific URLs with injectable parameters such as 'sensor', 'tcp_flags', and 'sortby' to exploit the vulnerabilities.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: AlienVault OSSIM Open Source SIEM 4.1
No auth needed
Prerequisites: Access to the target OSSIM web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/26406

Scores

EPSS 0.0140
EPSS Percentile 69.0%

Details

CWE
CWE-89
Status published
Products (1)
alienvault/open_source_security_information_management 4.1
Published Aug 20, 2013
Tracked Since Feb 18, 2026