CVE-2009-4373: High severity AlienVault Open Source Security Information Management vulnerability
Unrestricted file upload vulnerability in repository/repositoryattachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in ossiminstall/uploads/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4373?
CVE-2009-4373 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2009-4373?
To remediate CVE-2009-4373, upgrade to AlienVault OSSIM version 2.1.5-4 or later, which patches the vulnerability.
Which versions of AlienVault OSSIM are affected by CVE-2009-4373?
CVE-2009-4373 affects AlienVault OSSIM versions 2.1.5-1, 2.1.5-2, and 2.1.5-3.
What is the nature of the vulnerability in CVE-2009-4373?
CVE-2009-4373 is an unrestricted file upload vulnerability that enables the execution of arbitrary code by uploading malicious files.
Can CVE-2009-4373 be exploited remotely?
Yes, CVE-2009-4373 can be exploited remotely by an attacker without the need for local access.