7.5

CVE-2009-4372

Exploit
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary commands via shell metacharacters in the uniqueid parameter to (1) wcl.php, (2) storage_graphs.php, (3) storage_graphs2.php, (4) storage_graphs3.php, and (5) storage_graphs4.php in sem/.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.82% 0.908
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://osvdb.org/61151
http://osvdb.org/61152
http://osvdb.org/61153
http://osvdb.org/61154
http://osvdb.org/61155
http://secunia.com/advisories/37727
Vendor Advisory
http://www.alienvault.com/community.php?section=News
Exploit
http://www.cybsec.com/vuln/OSSIM_2_1_5_Remote_Command_Execution.pdf
Exploit
http://www.exploit-db.com/exploits/10480
Exploit
http://www.securityfocus.com/bid/37375
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/54843