CVE-2014-4153

AlienVault OSSIM <4.8.0 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-4153. PoCs published by James Fitts.

AI-analyzed exploit summary This exploit leverages an information disclosure vulnerability in Alienvault OSSIM's av-centerd Util.pm get_file function. It sends a crafted SOAP request to retrieve arbitrary file contents, such as /etc/shadow, due to insufficient sanitization of the $r_file parameter.

Description

The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.

Exploits (1)

exploitdb WORKING POC
by James Fitts · rubyremotelinux
https://www.exploit-db.com/exploits/42695

This exploit leverages an information disclosure vulnerability in Alienvault OSSIM's av-centerd Util.pm get_file function. It sends a crafted SOAP request to retrieve arbitrary file contents, such as /etc/shadow, due to insufficient sanitization of the $r_file parameter.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Alienvault OSSIM av-centerd (version not specified)
No auth needed
Prerequisites: Network access to the target's av-centerd service (port 40007)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://forums.alienvault.com/discussion/2806
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-14-207/
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59112

Scores

EPSS 0.0738
EPSS Percentile 93.6%

Details

CWE
CWE-200
Status published
Products (7)
alienvault/open_source_security_information_management 4.0
alienvault/open_source_security_information_management 4.3.3
alienvault/open_source_security_information_management 4.4
alienvault/open_source_security_information_management 4.5
alienvault/open_source_security_information_management 4.6
alienvault/open_source_security_information_management 4.6.1
alienvault/open_source_security_information_management < 4.7.0
Published Jun 18, 2014
Tracked Since Feb 18, 2026