CVE-2006-1590

medium

Description

Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Console for Intrusion Databases (ACID) 0.9.6b23 allows remote attackers to inject arbitrary web script or HTML via the (a) back parameter to base_graph_main.php, (b) netmask parameter to base_stat_ipaddr.php, or (c) submit parameter to base_qry_alert.php within BASE, or (d) query string to acid_main.php in ACID, which causes the request URI ($_SERVER['REQUEST_URI']) to be inserted into a refresh operation.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/25671

http://www.vupen.com/english/advisories/2006/1264

http://www.securityfocus.com/bid/17391

http://www.osvdb.org/24307

http://www.osvdb.org/20835

http://sourceforge.net/mailarchive/forum.php?thread_id=10064470&forum_id=42223

http://secunia.com/advisories/19544

Details

Source: Mitre, NVD

Published: 2006-04-03

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.07459