PT-2012-3125 · Base · Basic Analysis/Security Engine
Publicado
2012-02-18
·
Atualizado
2017-08-29
·
CVE-2012-1198
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Basic Analysis and Security Engine (BASE) version 1.4.5
Description
The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a create action, and then accessing it via a view action. This is made possible through the
base ag main.php file in the affected software.Recommendations
For Basic Analysis and Security Engine (BASE) version 1.4.5, consider restricting access to the
base ag main.php file to prevent remote attackers from uploading and executing arbitrary code until a patch is available. As a temporary workaround, avoid using the create and view actions in base ag main.php to minimize the risk of exploitation.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Basic Analysis/Security Engine