Exploitation Summary
EIP tracks 2 public exploits for CVE-2016-8582.
PoCs published by Peter Lapp, Peter Lapp, Mehmet Ince <[email protected]>, including Metasploit module exploits/linux/http/alienvault_exec.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Alienvault OSSIM/USM <=5.3.1 via the 'value' parameter in gauge.php. It allows blind SQLi or file-based exfiltration of data, such as password hashes, by leveraging serialized input and MySQL's INTO OUTFILE function.
Description
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Alienvault OSSIM/USM <=5.3.1 via the 'value' parameter in gauge.php. It allows blind SQLi or file-based exfiltration of data, such as password hashes, by leveraging serialized input and MySQL's INTO OUTFILE function.
This Metasploit module exploits a chain of vulnerabilities in AlienVault OSSIM/USM, including object injection, authentication bypass, and SQL injection, to achieve unauthenticated remote code execution as root. It hijacks an admin session, creates a rogue action with a Python payload, and triggers it via a failed SSH login attempt.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H