HTTP: INTO OUTFILE/DUMPFILE Command Injection

This signature detects attempts to perform SQL Injection. Dynamic web pages that accept user input without proper variable validation are vulnerable to arbitrary command injection.

Extended Description

A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.

Affected Products

Alienvault unified_security_management

Short Name
HTTP:SQL:INJ:INTO-OUTFILE
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2016-8582 Command INTO Injection OUTFILE/DUMPFILE
Release Date
07/11/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Alienvault

CVSS Score

7.5

Found a potential security threat?