CVE-2012-3834: SQL Injection
Published Jul 3, 2012
·Updated
SQL injection vulnerability in forensics/baseqrymain.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter.
Affected Software
1 affected component
AlienVault Open Source Security Information Management=3.1
Event History
Jul 3, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3834?
CVE-2012-3834 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2012-3834?
To fix CVE-2012-3834, upgrade to a patched version of AlienVault Open Source Security Information Management that addresses this vulnerability.
3
Who is affected by CVE-2012-3834?
CVE-2012-3834 affects users of AlienVault Open Source Security Information Management version 3.1.
4
What type of vulnerability is CVE-2012-3834?
CVE-2012-3834 is an SQL injection vulnerability that allows for arbitrary SQL command execution.
5
Can CVE-2012-3834 be exploited remotely?
Yes, CVE-2012-3834 can be exploited remotely by authenticated users.