VYPR

Os Sim

by Open Source Security Information Management

CVEs (2)

  • CVE-2008-0919Feb 22, 2008
    risk 0.04cvss epss 0.08

    Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter.

  • CVE-2008-0920Feb 22, 2008
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.