Lucene search

K
cvelistMitreCVELIST:CVE-2009-4373
HistoryDec 21, 2009 - 4:00 p.m.

CVE-2009-4373

2009-12-2116:00:00
mitre
www.cve.org
2
file upload vulnerability
alienvault ossim
executable extension
remote code execution

AI Score

7.7

Confidence

Low

EPSS

0.021

Percentile

89.5%

Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in ossiminstall/uploads/.

AI Score

7.7

Confidence

Low

EPSS

0.021

Percentile

89.5%

Related for CVELIST:CVE-2009-4373