Lucene search

K
exploitdbYu-Chi DingEDB-ID:38781
HistoryOct 02, 2013 - 12:00 a.m.

Alienvault Open Source SIEM (OSSIM) 3.1 - 'date_from' Multiple SQL Injections

2013-10-0200:00:00
Yu-Chi Ding
www.exploit-db.com
13

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

40.2%

source: https://www.securityfocus.com/bid/62790/info

Open Source SIEM (OSSIM) is prone to multiple SQL-injection vulnerabilities.

A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Open Source SIEM (OSSIM) 4.3.0 and prior are vulnerable. 

http://www.example.com/RadarReport/radar-iso27001-potential.php?date_from=%Inject_Here%

http://www.example.com/RadarReport/radar-iso27001-A12IS_acquisition-pot.php?date_from=%Inject_Here% 

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

40.2%