CVE-2009-4839
Secureideas Basic Analysis And Security Engine < 1.4.4 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/base_roleadmin.php, (2) admin/base_useradmin.php, (3) base_conf_contents.php, (4) base_qry_sqlcalls.php, and (5) base_ag_main.php.
References (5)
Scores
EPSS
0.0033
EPSS Percentile
55.5%
Classification
CWE
CWE-79
Status
published
Affected Products (19)
secureideas/basic_analysis_and_security_engine
< 1.4.4
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
... and 4 more
Timeline
Published
May 06, 2010
Tracked Since
Feb 18, 2026