← All CVEs

CVE-2016-8582

critical · 9.8

A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.

9.8
CVSS
57.4%
EPSS (exploit prob.)
99th
EPSS percentile
2016-10-28
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
alienvaultopen_source_security_information_and_event_management<= 5.3.1
alienvaultunified_security_management<= 5.3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-8582