peter bassill · operator
$ cve CVE-2013-5321 JSON

CVE-2013-5321 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.4% (pctl 71)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to forensics/base_stat_alerts.php; the (4) ip_addr[1][8] or (5) port_type parameter to forensics/base_stat_ports.php; or the (6) sortby or (7) rvalue parameter in a search action to vulnmeter/index.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.37% — more likely to be exploited than 71% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2013-08-20
Last modified2026-06-16

Affected (1)

VendorProduct
alienvaultopen source security information management

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD