PoC Index

CVE-2013-5967

HIGH 7.5EPSS 19.0%

Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3) radar-iso27001-A11AccessControl-pot.php, (4) radar-iso27001-A10Com_OP_Mgnt-pot.php, or (5) radar-pci-potential.php in RadarReport/.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
19.02% chance of exploitation in the next 30 days, 97th percentile
Published
2013-10-09
Updated
2024-09-16

Metasploit modules (1)

ExploitDB entries (1)

References

Related