{"id":"UBUNTU-CVE-2013-5321","details":"Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to forensics/base_stat_alerts.php; the (4) ip_addr[1][8] or (5) port_type parameter to forensics/base_stat_ports.php; or the (6) sortby or (7) rvalue parameter in a search action to vulnmeter/index.php.","modified":"2026-04-22T09:25:01.756910Z","published":"2013-08-20T14:56:00Z","upstream":["CVE-2013-5321"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2013-5321"},{"type":"REPORT","url":"http://www.exploit-db.com/exploits/26406"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2013-5321"}],"affected":[{"package":{"name":"ossim","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ossim@1.8.16-4ubuntu1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.8.16-4ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"libossim1v5","binary_version":"1.8.16-4ubuntu1"},{"binary_name":"ossim-core","binary_version":"1.8.16-4ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-5321.json"}},{"package":{"name":"ossim","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/ossim@2.2.2-1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.8.20.3+ds-5build1","2.2.0-1","2.2.1-1","2.2.2-1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.2.2-1","binary_name":"libossim1"},{"binary_name":"ossim-core","binary_version":"2.2.2-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-5321.json"}},{"package":{"name":"ossim","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/ossim@2.9.1-2build1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.9.0-1","2.9.1-2","2.9.1-2build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libossim1","binary_version":"2.9.1-2build1"},{"binary_name":"ossim-core","binary_version":"2.9.1-2build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-5321.json"}}],"schema_version":"1.7.5","severity":[{"type":"Ubuntu","score":"medium"}]}