CVE-2016-7955

CVE-2016-7955

The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain sensitive information, modify the application, or execute arbitrary code as root via an "AV Report Scheduler" HTTP User-Agent header.

Source: CVE-2016-7955

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다