Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-1590
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1590

Description:
Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Console for Intrusion Databases (ACID) 0.9.6b23 allows remote attackers to inject arbitrary web script or HTML via the (a) back parameter to base_graph_main.php, (b) netmask parameter to base_stat_ipaddr.php, or (c) submit parameter to base_qry_alert.php within BASE, or (d) query string to acid_main.php in ACID, which causes the request URI ($_SERVER['REQUEST_URI']) to be inserted into a refresh operation.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/25671

SAID
  Secunia Advisory: SA19544

OSVDB
  24307
  20835

MLIST
  http://sourceforge.net/mailarchive/forum.php?thread_id=10064470&forum_id=42223

BID
  17391


Return to the previous page.