Cross-Site Scripting (XSS) Vulnerabilities in AlienVault OSSIM 4.3.0 and Earlier

Cross-Site Scripting (XSS) Vulnerabilities in AlienVault OSSIM 4.3.0 and Earlier

CVE-2013-5300 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php; the (3) section parameter to av_inventory/task_edit.php; the (4) profile parameter to nfsen/rrdgraph.php; or the (5) scan_server or (6) targets parameter to vulnmeter/simulate.php.

Learn more about our Web App Pen Testing.