TITLE: OSSIM Multiple SQL Injection Vulnerabilities SECUNIA ADVISORY ID: SA9695 VERIFY ADVISORY: http://www.secunia.com/advisories/9695/ CRITICAL: Moderately critical IMPACT: Security Bypass, Manipulation of data, Exposure of sensitive information WHERE: From remote SOFTWARE: OSSIM (Open Source Security Information Management) 0.x DESCRIPTION: Multiple vulnerabilities have been reported in OSSIM (Open Source Security Information Management), which can be exploited by malicious people to conduct SQL injection attacks. The vulnerabilities are caused due to missing input validation. This can be exploited to include arbitrary SQL code, which potentially could disclose sensitive information, allow manipulation of existing data or bypassing security restrictions. SOLUTION: Update to version 0.3.1-alpha: http://prdownloads.sourceforge.net/os-sim/os-sim-0.3.1-alpha.tgz?download ORIGINAL ADVISORY: http://sourceforge.net/project/shownotes.php?release_id=183230 ---------------------------------------------------------------------- Secunia recommends that you verify all advisories you receive, by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. Contact details: Web : http://www.secunia.com/ E-mail : support@secunia.com Tel : +45 7020 5144 Fax : +45 7020 5145 ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://www.secunia.com/sec_adv_unsubscribe/?email=packet@packetstormsecurity.org ----------------------------------------------------------------------