CVE-2013-5967: SQL Injection
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the datefrom parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12ISacquisition-pot.php, (3) radar-iso27001-A11AccessControl-pot.php, (4) radar-iso27001-A10ComOPMgnt-pot.php, or (5) radar-pci-potential.php in RadarReport/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5967?
CVE-2013-5967 is classified as a critical vulnerability that allows remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2013-5967?
To fix CVE-2013-5967, upgrade AlienVault Open Source Security Information Management to a version later than 4.3.
Which versions of AlienVault Open Source Security Information Management are affected by CVE-2013-5967?
CVE-2013-5967 affects AlienVault Open Source Security Information Management versions 4.3 and earlier.
What type of vulnerability is CVE-2013-5967?
CVE-2013-5967 is an SQL injection vulnerability.
Can CVE-2013-5967 be exploited remotely?
Yes, CVE-2013-5967 can be exploited remotely by attackers to execute malicious SQL commands.