7.5
CVSSv2

CVE-2005-3325

Published: 27/10/2005 Updated: 03/07/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote malicious users to execute arbitrary SQL commands via the sig[1] parameter and possibly other parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

acid analysis console for intrusion databases 0.9.6b20

secureideas basic analysis and security engine 1.2

Vendor Advisories

Debian Bug report logs - #426103 New upstream release with security fixes Package: php-xajax; Maintainer for php-xajax is Debian QA Group <packages@qadebianorg>; Source for php-xajax is src:php-xajax (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, 26 May 2007 10:15:06 UTC Severity: ...

Exploits

source: wwwsecurityfocuscom/bid/15199/info Basic Analysis And Security Engine is prone to an SQL injection vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query Successful exploitation could result in a compromise of the application, disclosure or modifi ...