Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

BASE < 1.4.3 XSS



The remote host is vulnerable to an HTML Injection attack


The remote host is running BASE, a web-based tool for analyzing alerts from one or more SNORT sensors. The version of BASE installed on the remote host allows a remote attacker to inject HTML and perform cross-site scripting (XSS) attacks against unsuspecting users. In order to inject the malicious code, the attacker would need the ability to log into the BASE system. Successful exploitation would result in the attacker executing script code within the browser of other BASE users. The two php scripts which are vulnerable to injection are: 'base_ag_main.php' and 'base_qry_main.php'.


Upgrade to BASE version 1.4.3 or later.