CVE-2009-4375: SQL Injection
SQL injection vulnerability in repository/repositoryattachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary SQL commands via the iddocument parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4375?
CVE-2009-4375 has a medium severity level due to its potential for SQL injection leading to unauthorized data access.
How do I fix CVE-2009-4375?
To fix CVE-2009-4375, upgrade the AlienVault Open Source Security Information Management software to version 2.1.5-4 or later.
What impact does CVE-2009-4375 have on affected systems?
CVE-2009-4375 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database.
Which versions of AlienVault are affected by CVE-2009-4375?
AlienVault OSSIM versions prior to 2.1.5-4, including 2.1.5, 2.1.5-1, 2.1.5-2, and 2.1.5-3, are affected by CVE-2009-4375.
How can I determine if my system is vulnerable to CVE-2009-4375?
Check if your version of AlienVault OSSIM is one of the affected versions prior to 2.1.5-4 to confirm vulnerability to CVE-2009-4375.