CVE-2013-5300: XSS
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php; the (3) section parameter to avinventory/taskedit.php; the (4) profile parameter to nfsen/rrdgraph.php; or the (5) scanserver or (6) targets parameter to vulnmeter/simulate.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5300?
CVE-2013-5300 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-5300?
To fix CVE-2013-5300, upgrade to AlienVault Open Source Security Information Management version 4.3.0 or later.
What are the affected versions for CVE-2013-5300?
CVE-2013-5300 affects AlienVault OSSIM versions prior to 4.3.0.
What types of attacks can CVE-2013-5300 facilitate?
CVE-2013-5300 can facilitate arbitrary web script or HTML injection leading to unauthorized actions on behalf of users.
Is CVE-2013-5300 exploitable remotely?
Yes, CVE-2013-5300 can be exploited remotely by attackers through manipulated web requests.