← Vulnerability feed

Vulnerability record · CVE-2012-3835 · published 3 July 2012

CVE-2012-3835: Alienvault open source security information management cross-site scripting vulnerability

Alienvault · Open Source Security Information Management

Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an error page.

4.3 CVSS 2.0 Medium EPSS 2.2% · top 18.0% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to top.php or (2) time[0][0] parameter to forensics/base_qry_main.php, which is not properly handled in an error page.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-3835 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-5158Alienvault open source security information management code injection vulnerabilityThe (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to exe…EPSS 3.7%10.0CVE-2014-5210Alienvault open source security information management code injection vulnerabilityThe av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (…EPSS 15%10.0CVE-2014-4151Alienvault open source security information management code injection vulnerabilityThe av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a craft…EPSS 7.3%10.0CVE-2014-4152Alienvault open source security information management code injection vulnerabilityThe av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, rel…EPSS 5.8%10.0CVE-2014-3804AlienVault OSSIM av-centerd SOAP service command injectionThe av-centerd SOAP service in AlienVault OSSIM before 4.7.0 fails to properly validate input in several request types, allowing remote command injec…EPSS 72%analysed10.0CVE-2014-3805Alienvault open source security information management code injection vulnerabilityThe av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2)…EPSS 13%9.8CVE-2018-7279Alienvault open source security information management vulnerabilityA remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.EPSS 2.4%7.8CVE-2014-4153Alienvault open source security information management information exposure vulnerabilityThe av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.EPSS 7.4%

Source: NIST National Vulnerability Database (record CVE-2012-3835), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.