Записи secureideas
13 опубликованных записей вендора secureideas.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 7,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2012-1198Proof of concept | base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents secureideas · basic analysis and security engine · CWE-20 | Высокая7,5 | — | 5,3 % | 17 февр. 2012 г. |
31Наблюдать | CVE-2012-1199Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbisecureideas · basic analysis and security engine · CWE-94 | Высокая7,5 | — | 3,4 % | 17 февр. 2012 г. |
31Наблюдать | CVE-2005-3325Proof of concept | Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qryacid · analysis console for intrusion databases · CWE-89 | Высокая7,5 | — | 2,6 % | 27 окт. 2005 г. |
31Наблюдать | CVE-2007-5578Эксплойта нет | Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers secureideas · basic analysis and security engine · CWE-287 | Высокая7,5 | — | 1,8 % | 18 окт. 2007 г. |
30Наблюдать | CVE-2009-4592Эксплойта нет | Unspecified vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to inclusecureideas · base | Высокая7,5 | — | 1,4 % | 7 янв. 2010 г. |
30Наблюдать | CVE-2012-1017Proof of concept | Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to exesecureideas · base · CWE-89 | Высокая7,5 | — | 1,3 % | 7 февр. 2012 г. |
30Наблюдать | CVE-2009-4591Эксплойта нет | SQL injection vulnerability in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to execute arbitrary SQL commasecureideas · base · CWE-89 | Высокая7,5 | — | 1,1 % | 7 янв. 2010 г. |
30Наблюдать | CVE-2009-4838Эксплойта нет | SQL injection vulnerability in base_ag_common.php in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allows remote attackers to exesecureideas · basic analysis and security engine · CWE-89 | Высокая7,5 | — | 1,1 % | 6 мая 2010 г. |
17Наблюдать | CVE-2007-6156Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in base_qry_main.php in Base Analysis and Security Engine (BASE) before 1.3.9 allow remosecureideas · basic analysis and security engine · CWE-79 | Средняя4,3 | — | 1,3 % | 28 нояб. 2007 г. |
17Наблюдать | CVE-2009-4837Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow remote attackers to insecureideas · basic analysis and security engine · CWE-79 | Средняя4,3 | — | 1,1 % | 6 мая 2010 г. |
17Наблюдать | CVE-2009-4590Эксплойта нет | Cross-site scripting (XSS) vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attsecureideas · base · CWE-79 | Средняя4,3 | — | 1,1 % | 7 янв. 2010 г. |
17Наблюдать | CVE-2005-4878Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 andacid · analysis console for intrusion databases · CWE-79 | Средняя4,3 | — | 1,1 % | 18 февр. 2009 г. |
17Наблюдать | CVE-2009-4839Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote asecureideas · basic analysis and security engine · CWE-79 | Средняя4,3 | — | 1,1 % | 6 мая 2010 г. |
- CVE-2012-119832Наблюдать
base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %secureideas · basic analysis and security engine17 февр. 2012 г.
- CVE-2012-119931Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbi
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %secureideas · basic analysis and security engine17 февр. 2012 г.
- CVE-2005-332531Наблюдать
Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %acid · analysis console for intrusion databases27 окт. 2005 г.
- CVE-2007-557831Наблюдать
Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %secureideas · basic analysis and security engine18 окт. 2007 г.
- CVE-2009-459230Наблюдать
Unspecified vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to inclu
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %secureideas · base7 янв. 2010 г.
- CVE-2012-101730Наблюдать
Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to exe
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %secureideas · base7 февр. 2012 г.
- CVE-2009-459130Наблюдать
SQL injection vulnerability in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to execute arbitrary SQL comma
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %secureideas · base7 янв. 2010 г.
- CVE-2009-483830Наблюдать
SQL injection vulnerability in base_ag_common.php in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allows remote attackers to exe
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %secureideas · basic analysis and security engine6 мая 2010 г.
- CVE-2007-615617Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in base_qry_main.php in Base Analysis and Security Engine (BASE) before 1.3.9 allow remo
СредняяCVSS 4,3Эксплойта нетEPSS 1 %secureideas · basic analysis and security engine28 нояб. 2007 г.
- CVE-2009-483717Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow remote attackers to in
СредняяCVSS 4,3Эксплойта нетEPSS 1 %secureideas · basic analysis and security engine6 мая 2010 г.
- CVE-2009-459017Наблюдать
Cross-site scripting (XSS) vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote att
СредняяCVSS 4,3Эксплойта нетEPSS 1 %secureideas · base7 янв. 2010 г.
- CVE-2005-487817Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and
СредняяCVSS 4,3Эксплойта нетEPSS 1 %acid · analysis console for intrusion databases18 февр. 2009 г.
- CVE-2009-483917Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote a
СредняяCVSS 4,3Эксплойта нетEPSS 1 %secureideas · basic analysis and security engine6 мая 2010 г.