CVE-2016-6913: XSS
Cross-site scripting (XSS) vulnerability in AlienVault OSSIM before 5.3 and USM before 5.3 allows remote attackers to inject arbitrary web script or HTML via the back parameter to ossim/conf/reload.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6913?
CVE-2016-6913 is rated as a high severity vulnerability due to its potential for remote code execution via cross-site scripting.
How do I fix CVE-2016-6913?
To fix CVE-2016-6913, upgrade AlienVault OSSIM or USM to version 5.3 or later.
What types of attacks does CVE-2016-6913 enable?
CVE-2016-6913 enables remote attackers to execute arbitrary web scripts or HTML, leading to potential data theft or session hijacking.
Which versions of AlienVault are affected by CVE-2016-6913?
CVE-2016-6913 affects AlienVault OSSIM versions prior to 5.3 and Unified Security Management versions prior to 5.3.
Is CVE-2016-6913 easy to exploit?
Yes, CVE-2016-6913 can be easily exploited by sending specially crafted input to the affected reload.php script.