CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
Percentile
62.4%
SQL injection vulnerability in forensics/base_qry_main.php in AlienVault
Open Source Security Information Management (OSSIM) 3.1 allows remote
authenticated users to execute arbitrary SQL commands via the time[0][0]
parameter.
Author | Note |
---|---|
msalvatore | OSSIM is not Open Source Software Image Map |
secunia.com/advisories/49005
www.darksecurity.de/index.php?/211-KORAMIS-ADV2012-002-Alienvault-OSSIM-Open-Source-SIEM-3.1-Multiple-security-vulnerabilities.html
www.exploit-db.com/exploits/18800
www.koramis.com/advisories/2012/KORAMIS-ADV2012-002.txt
xforce.iss.net/xforce/xfdb/75290
launchpad.net/bugs/cve/CVE-2012-3834
nvd.nist.gov/vuln/detail/CVE-2012-3834
security-tracker.debian.org/tracker/CVE-2012-3834
www.cve.org/CVERecord?id=CVE-2012-3834