VulnerabilityModified
CVE-2009-3440
Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu).
MEDIUM 4.3EPSS 1.45%
Does this matter?
Lower severity and a low EPSS score (1.45%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu).
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.45% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- alienvault/ossim
- Source
- cve@mitre.org
References
- http://dsecrg.com/pages/vul/show.php?id=155Exploit
- http://secunia.com/advisories/36867Vendor Advisory
- http://www.securityfocus.com/archive/1/506663/100/0/threaded
- http://www.securityfocus.com/bid/36504Exploit
- http://dsecrg.com/pages/vul/show.php?id=155Exploit
- http://secunia.com/advisories/36867Vendor Advisory
- http://www.securityfocus.com/archive/1/506663/100/0/threaded
- http://www.securityfocus.com/bid/36504Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.