Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-7955
Description:The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain sensitive information, modify the application, or execute arbitrary code as root via an "AV Report Scheduler" HTTP User-Agent header.
Test IDs: 1.3.6.1.4.1.25623.1.0.106617  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-7955
Bugtraq: 20170306 CVE-2016-7955 - Alienvault OSSIM/USM Authentication Bypass (Google Search)
http://www.securityfocus.com/archive/1/540224/100/0/threaded
http://www.zerodayinitiative.com/advisories/ZDI-16-517/




© 1998-2025 E-Soft Inc. All rights reserved.