CVE Database
/

CVE-2006-1590

Back to search

CVE-2006-1590

Published: Apr 3, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Console for Intrusion Databases (ACID) 0.9.6b23 allows remote attackers to inject arbitrary web script or HTML via the (a) back parameter to base_graph_main.php, (b) netmask parameter to base_stat_ipaddr.php, or (c) submit parameter to base_qry_alert.php within BASE, or (d) query string to acid_main.php in ACID, which causes the request URI ($_SERVER['REQUEST_URI']) to be inserted into a refresh operation.

VendorProductVersions

n/a

n/a

affected
n/a

References

17391
vdb-entry
x_refsource_BID
ADV-2006-1264
vdb-entry
x_refsource_VUPEN
20835
vdb-entry
x_refsource_OSVDB
base-multiple-scripts-xss(25671)
vdb-entry
x_refsource_XF
24307
vdb-entry
x_refsource_OSVDB
19544
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now