|
|
|
|
|
|
|
| |
BASE base_maintenance.php Authentication Bypass |
|
| This script is Copyright (C) 2006-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 21174 (base_auth_bypass.nasl) |
| Bugtraq ID | 17354
|
| CVE ID | CVE-2006-1505
|
|
| Description: |
Synopsis :
The remote web server contains a PHP script that is prone to an
authentication bypass vulnerability.
Description :
The remote host is running BASE, a web-based tool for analyzing alerts
from one or more SNORT sensors.
The version of BASE installed on the remote host allows a remote
attacker to bypass authentication to the 'base_maintenance.php' script
and then perform selected maintenance tasks.
See also :
http://sourceforge.net/project/shownotes.php?release_id=402956&group_id=103348
Solution :
Upgrade to BASE version 1.2.4 or later.
Risk factor :
Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
|
|
|
|
|
|