Secunia Research Advisory - OSSIM, or Open Source Security Information Management, version 0.x is vulnerable to multiple SQL injection attacks.
8314c356a3099a783137c34457c8be16febc4795cee9980efdebc73d5864b4d5
TITLE:
OSSIM Multiple SQL Injection Vulnerabilities
SECUNIA ADVISORY ID:
SA9695
VERIFY ADVISORY:
http://www.secunia.com/advisories/9695/
CRITICAL:
Moderately critical
IMPACT:
Security Bypass, Manipulation of data, Exposure of sensitive
information
WHERE:
From remote
SOFTWARE:
OSSIM (Open Source Security Information Management) 0.x
DESCRIPTION:
Multiple vulnerabilities have been reported in OSSIM (Open Source
Security Information Management), which can be exploited by malicious
people to conduct SQL injection attacks.
The vulnerabilities are caused due to missing input validation. This
can be exploited to include arbitrary SQL code, which potentially
could disclose sensitive information, allow manipulation of existing
data or bypassing security restrictions.
SOLUTION:
Update to version 0.3.1-alpha:
http://prdownloads.sourceforge.net/os-sim/os-sim-0.3.1-alpha.tgz?download
ORIGINAL ADVISORY:
http://sourceforge.net/project/shownotes.php?release_id=183230
----------------------------------------------------------------------
Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
Contact details:
Web : http://www.secunia.com/
E-mail : support@secunia.com
Tel : +45 7020 5144
Fax : +45 7020 5145
----------------------------------------------------------------------