CVE-2016-8582

CRITICAL

AlienVault OSSIM & USM <5.3.2 - SQL Injection

Title source: llm

Description

A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Peter Lapp · textwebappsphp
https://www.exploit-db.com/exploits/40684
metasploit WORKING POC EXCELLENT
by Peter Lapp, Mehmet Ince <[email protected]> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/alienvault_exec.rb

Scores

CVSS v3 9.8
EPSS 0.8055
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
alienvault/open_source_security_information_and_event_management < 5.3.1
alienvault/unified_security_management < 5.3.1
Published Oct 28, 2016
Tracked Since Feb 18, 2026