AlienVault Open Source SIEM (OSSIM) Multiple Cross Site Scripting Vulnerabilities
BID:61456
Info
AlienVault Open Source SIEM (OSSIM) Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 61456 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2013 12:00AM |
| Updated: | Jul 25 2013 12:00AM |
| Credit: | xistence |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
AlienVault Open Source SIEM (OSSIM) Multiple Cross Site Scripting Vulnerabilities
Open Source SIEM (OSSIM) is prone to multiple cross-site-scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Open Source SIEM (OSSIM) 4.2.3 is vulnerable; other versions may also be affected.
Open Source SIEM (OSSIM) is prone to multiple cross-site-scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Open Source SIEM (OSSIM) 4.2.3 is vulnerable; other versions may also be affected.
Exploit / POC
AlienVault Open Source SIEM (OSSIM) Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example data is available:
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example data is available:
Solution / Fix
AlienVault Open Source SIEM (OSSIM) Multiple Cross Site Scripting Vulnerabilities
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
AlienVault Open Source SIEM (OSSIM) Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Alienvault Homepage (Alienvault)