secureideas records
13 published records for vendor secureideas.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 7.7%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2012-1198Proof of concept | base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents secureideas · basic analysis and security engine · CWE-20 | High7.5 | — | 5.3% | Feb 17, 2012 |
31Monitor | CVE-2012-1199Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbisecureideas · basic analysis and security engine · CWE-94 | High7.5 | — | 3.4% | Feb 17, 2012 |
31Monitor | CVE-2005-3325Proof of concept | Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qryacid · analysis console for intrusion databases · CWE-89 | High7.5 | — | 2.6% | Oct 27, 2005 |
31Monitor | CVE-2007-5578No exploit | Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers secureideas · basic analysis and security engine · CWE-287 | High7.5 | — | 1.8% | Oct 18, 2007 |
30Monitor | CVE-2009-4592No exploit | Unspecified vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to inclusecureideas · base | High7.5 | — | 1.4% | Jan 7, 2010 |
30Monitor | CVE-2012-1017Proof of concept | Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to exesecureideas · base · CWE-89 | High7.5 | — | 1.3% | Feb 7, 2012 |
30Monitor | CVE-2009-4591No exploit | SQL injection vulnerability in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to execute arbitrary SQL commasecureideas · base · CWE-89 | High7.5 | — | 1.1% | Jan 7, 2010 |
30Monitor | CVE-2009-4838No exploit | SQL injection vulnerability in base_ag_common.php in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allows remote attackers to exesecureideas · basic analysis and security engine · CWE-89 | High7.5 | — | 1.1% | May 6, 2010 |
17Monitor | CVE-2007-6156No exploit | Multiple cross-site scripting (XSS) vulnerabilities in base_qry_main.php in Base Analysis and Security Engine (BASE) before 1.3.9 allow remosecureideas · basic analysis and security engine · CWE-79 | Medium4.3 | — | 1.3% | Nov 28, 2007 |
17Monitor | CVE-2009-4837No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow remote attackers to insecureideas · basic analysis and security engine · CWE-79 | Medium4.3 | — | 1.1% | May 6, 2010 |
17Monitor | CVE-2009-4590No exploit | Cross-site scripting (XSS) vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attsecureideas · base · CWE-79 | Medium4.3 | — | 1.1% | Jan 7, 2010 |
17Monitor | CVE-2005-4878No exploit | Multiple cross-site scripting (XSS) vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 andacid · analysis console for intrusion databases · CWE-79 | Medium4.3 | — | 1.1% | Feb 18, 2009 |
17Monitor | CVE-2009-4839No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote asecureideas · basic analysis and security engine · CWE-79 | Medium4.3 | — | 1.1% | May 6, 2010 |
- CVE-2012-119832Monitor
base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents
HighCVSS 7.5Proof of conceptEPSS 5%secureideas · basic analysis and security engineFeb 17, 2012
- CVE-2012-119931Monitor
Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbi
HighCVSS 7.5Proof of conceptEPSS 3%secureideas · basic analysis and security engineFeb 17, 2012
- CVE-2005-332531Monitor
Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry
HighCVSS 7.5Proof of conceptEPSS 3%acid · analysis console for intrusion databasesOct 27, 2005
- CVE-2007-557831Monitor
Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers
HighCVSS 7.5No exploitEPSS 2%secureideas · basic analysis and security engineOct 18, 2007
- CVE-2009-459230Monitor
Unspecified vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to inclu
HighCVSS 7.5No exploitEPSS 1%secureideas · baseJan 7, 2010
- CVE-2012-101730Monitor
Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to exe
HighCVSS 7.5Proof of conceptEPSS 1%secureideas · baseFeb 7, 2012
- CVE-2009-459130Monitor
SQL injection vulnerability in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to execute arbitrary SQL comma
HighCVSS 7.5No exploitEPSS 1%secureideas · baseJan 7, 2010
- CVE-2009-483830Monitor
SQL injection vulnerability in base_ag_common.php in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allows remote attackers to exe
HighCVSS 7.5No exploitEPSS 1%secureideas · basic analysis and security engineMay 6, 2010
- CVE-2007-615617Monitor
Multiple cross-site scripting (XSS) vulnerabilities in base_qry_main.php in Base Analysis and Security Engine (BASE) before 1.3.9 allow remo
MediumCVSS 4.3No exploitEPSS 1%secureideas · basic analysis and security engineNov 28, 2007
- CVE-2009-483717Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow remote attackers to in
MediumCVSS 4.3No exploitEPSS 1%secureideas · basic analysis and security engineMay 6, 2010
- CVE-2009-459017Monitor
Cross-site scripting (XSS) vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote att
MediumCVSS 4.3No exploitEPSS 1%secureideas · baseJan 7, 2010
- CVE-2005-487817Monitor
Multiple cross-site scripting (XSS) vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and
MediumCVSS 4.3No exploitEPSS 1%acid · analysis console for intrusion databasesFeb 18, 2009
- CVE-2009-483917Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote a
MediumCVSS 4.3No exploitEPSS 1%secureideas · basic analysis and security engineMay 6, 2010