CVE-2016-8582
CRITICALAlienVault OSSIM & USM <5.3.2 - SQL Injection
Title source: llmDescription
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Peter Lapp · textwebappsphp
https://www.exploit-db.com/exploits/40684
metasploit
WORKING POC
EXCELLENT
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/alienvault_exec.rb
Scores
CVSS v3
9.8
EPSS
0.8055
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (2)
alienvault/open_source_security_information_and_event_management
< 5.3.1
alienvault/unified_security_management
< 5.3.1
Published
Oct 28, 2016
Tracked Since
Feb 18, 2026