Security Advisory

CVE-2009-3439

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-09-28 22:00:00
Last updated 2024-08-07 06:31:09
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple SQL injection vulnerabilities in Open Source Security Information Management (OSSIM) before 2.1.2 allow remote authenticated users to execute arbitrary SQL commands via the id_document parameter to (1) repository_document.php, (2) repository_links.php, and (3) repository_editdocument.php in repository/; the (4) group parameter to policy/getpolicy.php; the name parameter to (5) host/newhostgroupform.php and (6) net/modifynetform.php; and unspecified other vectors related to the policy menu.