CVE Database
/

CVE-2013-5300

Back to search

CVE-2013-5300

Published: Aug 15, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php; the (3) section parameter to av_inventory/task_edit.php; the (4) profile parameter to nfsen/rrdgraph.php; or the (5) scan_server or (6) targets parameter to vulnmeter/simulate.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

95814
vdb-entry
x_refsource_OSVDB
95818
vdb-entry
x_refsource_OSVDB
54264
third-party-advisory
x_refsource_SECUNIA
95816
vdb-entry
x_refsource_OSVDB
54287
third-party-advisory
x_refsource_SECUNIA
61456
vdb-entry
x_refsource_BID
95813
vdb-entry
x_refsource_OSVDB
95817
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now