CVE-2005-4878
ACID 0.9.6b20 & BASE 1.2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to inject arbitrary web script or HTML via the sig[1] parameter and possibly other parameters, a different vulnerability than CVE-2007-6156.
References (5)
Scores
EPSS
0.0033
EPSS Percentile
55.5%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
acid/analysis_console_for_intrusion_databases
secureideas/basic_analysis_and_security_engine
n/a/n/a
Timeline
Published
Feb 18, 2009
Tracked Since
Feb 18, 2026