peter bassill · operator
$ cve CVE-2016-8582 JSON

CVE-2016-8582 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 57.4% (pctl 99)

Patch early

A public exploit exists.

Description

A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS57.43% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2016-10-28
Last modified2026-06-17

Affected (2)

VendorProduct
alienvaultopen source security information and event management
alienvaultunified security management

Public exploits

SourceTitleDate
exploit-dbAlienvault OSSIM/USM 5.3.1 - SQL Injection2016-11-02

References

→ the Explorer  ·  watch your stack  ·  NVD