The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_file request.Referenceshttp://forums.alienvault.com/discussion/2806http://www.zerodayinitiative.com/advisories/ZDI-14-205/http://secunia.com/advisories/59112