ZeroHour

CVE-2016-8580

CVSS 3.0
9.8 critical
EPSS
7%p94
Published
()
Modified
Description

PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.

Vendors
alienvault
Products
open source security information and event management, unified security management
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.