A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAlienvault Open Source Security Information And Event Management
APPAlienvault≤ 5.3.1Alienvault Unified Security Management
APPAlienvault≤ 5.3.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLi
CWE
Related vulnerabilities
CVE-2018-7279CRITICAL9.8PL ✓same product
RCE w AlienVault USM i OSSIM przed wersją 5.5.1
CVE-2017-6972CRITICAL9.8PL ✓same product
AlienVault USM/OSSIM i NfSen – błąd porzucania uprawnień, kod Perl uruchamiany jako root
CVE-2016-7955CRITICAL9.8PL ✓same product
Auth Bypass w AlienVault OSSIM/USM via nagłówka HTTP User-Agent
CVE-2016-8580CRITICAL9.8PL ✓same product
PHP Object Injection w AlienVault OSSIM/USM — zdalne wykonanie kodu
CVE-2017-6970HIGH8.4same product
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands i...