CVE-2009-4839

Secureideas Basic Analysis And Security Engine < 1.4.4 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/base_roleadmin.php, (2) admin/base_useradmin.php, (3) base_conf_contents.php, (4) base_qry_sqlcalls.php, and (5) base_ag_main.php.

Scores

EPSS 0.0033
EPSS Percentile 55.5%

Classification

CWE
CWE-79
Status published

Affected Products (19)

secureideas/basic_analysis_and_security_engine < 1.4.4
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
secureideas/basic_analysis_and_security_engine
... and 4 more

Timeline

Published May 06, 2010
Tracked Since Feb 18, 2026