Basic Analysis and Security Engine Multiple Unspecified Cross Site Scripting Vulnerabilities
BID:33985
Info
Basic Analysis and Security Engine Multiple Unspecified Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 33985 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-4878 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2005 12:00AM |
| Updated: | Mar 05 2009 10:46PM |
| Credit: | Debian |
| Vulnerable: |
Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 BASE Basic Analysis and Security Engine 1.2 ACID Acidlab 0.9.6 |
| Not Vulnerable: |
BASE Basic Analysis and Security Engine 1.2.1 |
Discussion
Basic Analysis and Security Engine Multiple Unspecified Cross Site Scripting Vulnerabilities
Basic Analysis and Security Engine (BASE) is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
Versions prior to BASE 1.2.1 are vulnerable.
Basic Analysis and Security Engine (BASE) is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
Versions prior to BASE 1.2.1 are vulnerable.
Exploit / POC
Basic Analysis and Security Engine Multiple Unspecified Cross Site Scripting Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Basic Analysis and Security Engine Multiple Unspecified Cross Site Scripting Vulnerabilities
Solution:
The vendor has released updates. Please contact the vendor for details.
ACID Acidlab 0.9.6
BASE Basic Analysis and Security Engine 1.2
Solution:
The vendor has released updates. Please contact the vendor for details.
ACID Acidlab 0.9.6
-
Debian acidlab-doc_0.9.6b20-10.1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/acidlab/acidlab-doc_0.9 .6b20-10.1_all.deb -
Debian acidlab-mysql_0.9.6b20-10.1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/acidlab/acidlab-mysql_0 .9.6b20-10.1_all.deb -
Debian acidlab-pgsql_0.9.6b20-10.1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/acidlab/acidlab-pgsql_0 .9.6b20-10.1_all.deb -
Debian acidlab_0.9.6b20-10.1_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/a/acidlab/acidlab_0.9.6b2 0-10.1_all.deb -
Debian acidlab_0.9.6b20-2.1_all.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/a/acidlab/acidlab_0.9.6b2 0-2.1_all.deb
BASE Basic Analysis and Security Engine 1.2
-
BASE base-1.2.1.tar.gz
http://prdownloads.sourceforge.net/secureideas/base-1.2.1.tar.gz?downl oad
References
Basic Analysis and Security Engine Multiple Unspecified Cross Site Scripting Vulnerabilities
References:
References: