Back
CVE-2016-8582
CRITICAL
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
Published: Oct 28, 2016
Modified: Jun 17, 2026
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| alienvault | open_source_security_information_and_event_management | * |
| alienvault | unified_security_management | * |
GitHub Security Advisory GHSA-pv32-m85p-f6rw
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an...
References (6)
- http://www.securityfocus.com/bid/93866
- https://www.alienvault.com/forums/discussion/7766/security-advisory-alienvault-5-3-2-address-70-vulnerabilities Vendor Advisory
- https://www.exploit-db.com/exploits/40684/
- http://www.securityfocus.com/bid/93866
- https://www.alienvault.com/forums/discussion/7766/security-advisory-alienvault-5-3-2-address-70-vulnerabilities Vendor Advisory
- https://www.exploit-db.com/exploits/40684/
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
57.43%
Top 1% most likely to be exploited
Threat Score
56.4 / 100
Data Sources
NVD
EPSS
GitHub