CVE-2012-3834

SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:alienvault:open_source_security_information_management:3.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:41

Type Values Removed Values Added
References () http://secunia.com/advisories/49005 - Vendor Advisory () http://secunia.com/advisories/49005 - Vendor Advisory
References () http://www.darksecurity.de/index.php?/211-KORAMIS-ADV2012-002-Alienvault-OSSIM-Open-Source-SIEM-3.1-Multiple-security-vulnerabilities.html - Exploit () http://www.darksecurity.de/index.php?/211-KORAMIS-ADV2012-002-Alienvault-OSSIM-Open-Source-SIEM-3.1-Multiple-security-vulnerabilities.html - Exploit
References () http://www.exploit-db.com/exploits/18800 - Exploit () http://www.exploit-db.com/exploits/18800 - Exploit
References () http://www.koramis.com/advisories/2012/KORAMIS-ADV2012-002.txt - Exploit () http://www.koramis.com/advisories/2012/KORAMIS-ADV2012-002.txt - Exploit
References () http://www.securityfocus.com/bid/53331 - Exploit () http://www.securityfocus.com/bid/53331 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/75290 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/75290 -

Information

Published : 2012-07-03 22:55

Updated : 2024-11-21 01:41


NVD link : CVE-2012-3834

Mitre link : CVE-2012-3834

CVE.ORG link : CVE-2012-3834


JSON object : View

Products Affected

alienvault

  • open_source_security_information_management
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')