CVE-2016-8580
CRITICALAlienVault OSSIM & USM <5.3.2 - Code Injection
Title source: llmDescription
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Peter Lapp · textwebappsphp
https://www.exploit-db.com/exploits/40682
Scores
CVSS v3
9.8
EPSS
0.1256
EPSS Percentile
94.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-284
Status
published
Products (2)
alienvault/open_source_security_information_and_event_management
< 5.3.1
alienvault/unified_security_management
< 5.3.1
Published
Oct 28, 2016
Tracked Since
Feb 18, 2026