CVE-2009-3440: XSS
Published Sep 28, 2009
·Updated
Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu).
Affected Software
3 affected components
AlienVault OSSIM<=2.1
AlienVault OSSIM=1.0.4
AlienVault OSSIM=1.0.6
Event History
Sep 28, 2009
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3440?
CVE-2009-3440 has a medium severity level due to its potential to allow remote code execution through XSS attacks.
2
How do I fix CVE-2009-3440?
To fix CVE-2009-3440, upgrade to OSSIM version 2.1.2 or later.
3
What types of attacks does CVE-2009-3440 enable?
CVE-2009-3440 enables attackers to conduct cross-site scripting attacks that can execute arbitrary web scripts or HTML.
4
Which versions of OSSIM are affected by CVE-2009-3440?
CVE-2009-3440 affects OSSIM versions prior to 2.1.2, including versions 1.0.4 and 1.0.6.
5
Who is impacted by CVE-2009-3440?
Users of OSSIM versions before 2.1.2 are at risk and should take immediate action to secure their installations.