CVE-2012-3835
Publication date 3 July 2012
Last updated 24 July 2024
Ubuntu priority
Description
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an error page.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ossim | ||
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
Notes
References
Other references
- http://xforce.iss.net/xforce/xfdb/75297
- http://www.koramis.com/advisories/2012/KORAMIS-ADV2012-002.txt
- http://www.exploit-db.com/exploits/18800
- http://www.darksecurity.de/index.php?/211-KORAMIS-ADV2012-002-Alienvault-OSSIM-Open-Source-SIEM-3.1-Multiple-security-vulnerabilities.html
- http://secunia.com/advisories/49005
- https://www.cve.org/CVERecord?id=CVE-2012-3835