CVE-2012-1017

BASE 1.4.5 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary SQL commands via the (1) ip_addr[0][1], (2) ip_addr[0][2], or (3) ip_addr[0][9] parameters.

Exploits (1)

exploitdb WORKING POC
by a.kadir altan · textwebappsphp
https://www.exploit-db.com/exploits/18465

References (4)

Core 4
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18465
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47857
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51874
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72998

Scores

EPSS 0.0086
EPSS Percentile 75.1%

Details

CWE
CWE-89
Status published
Products (1)
secureideas/base 1.4.5
Published Feb 08, 2012
Tracked Since Feb 18, 2026