AlienVault OSSIM and Unified Security Management 'newpolicyform.php' SQL Injection Vulnerability
BID:67312
Info
AlienVault OSSIM and Unified Security Management 'newpolicyform.php' SQL Injection Vulnerability
| Bugtraq ID: | 67312 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-5383 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2014 12:00AM |
| Updated: | Aug 22 2014 12:43PM |
| Credit: | Chris Hebert |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
AlienVault OSSIM and Unified Security Management 'newpolicyform.php' SQL Injection Vulnerability
AlienVault OSSIM and Unified Security Management are prone to an SQL-injection vulnerability because they fail to properly sanitize user-supplied input before using it in an SQL query.
An attacker can leverage this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
AlienVault OSSIM and AlienVault Unified Security Management prior to 4.7.0 are vulnerable.
NOTE: This BID initially referenced CVE-2014-3804 and CVE-2014-3805. These issues are now described in BID 67999 and BID 67998.
AlienVault OSSIM and Unified Security Management are prone to an SQL-injection vulnerability because they fail to properly sanitize user-supplied input before using it in an SQL query.
An attacker can leverage this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
AlienVault OSSIM and AlienVault Unified Security Management prior to 4.7.0 are vulnerable.
NOTE: This BID initially referenced CVE-2014-3804 and CVE-2014-3805. These issues are now described in BID 67999 and BID 67998.
Exploit / POC
AlienVault OSSIM and Unified Security Management 'newpolicyform.php' SQL Injection Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
AlienVault OSSIM and Unified Security Management 'newpolicyform.php' SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
AlienVault OSSIM and Unified Security Management 'newpolicyform.php' SQL Injection Vulnerability
References:
References:
- Alienvault Homepage (Alienvault)