CVE-2016-8580
—CVSS 3.0
9.8 critical
EPSS
7%p94
Published
()
Modified
Description
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.
- Vendors
- alienvault
- Products
- open source security information and event management, unified security management
- Weakness
- CWE-284
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.