SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:41
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/49005 - Vendor Advisory | |
References | () http://www.darksecurity.de/index.php?/211-KORAMIS-ADV2012-002-Alienvault-OSSIM-Open-Source-SIEM-3.1-Multiple-security-vulnerabilities.html - Exploit | |
References | () http://www.exploit-db.com/exploits/18800 - Exploit | |
References | () http://www.koramis.com/advisories/2012/KORAMIS-ADV2012-002.txt - Exploit | |
References | () http://www.securityfocus.com/bid/53331 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/75290 - |
Information
Published : 2012-07-03 22:55
Updated : 2024-11-21 01:41
NVD link : CVE-2012-3834
Mitre link : CVE-2012-3834
CVE.ORG link : CVE-2012-3834
JSON object : View
Products Affected
alienvault
- open_source_security_information_management
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')