CVE-2016-8582

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
28/10/2016
Last modified:
12/04/2025

Description

A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:alienvault:open_source_security_information_and_event_management:*:*:*:*:*:*:*:* 5.3.1 (including)
cpe:2.3:a:alienvault:unified_security_management:*:*:*:*:*:*:*:* 5.3.1 (including)