PT-2005-4135 · Acid+1 · Acid+1

Remco Verhoef

·

Published

2005-10-27

·

Updated

2012-07-03

·

CVE-2005-3325

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Analysis Console for Intrusion Databases (ACID) version 0.9.6b20 Basic Analysis and Security Engine (BASE) version 1.2
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through SQL injection vulnerabilities in certain console scripts, including acid qry main.php in ACID and base qry main.php in BASE. The sig[1] parameter is specifically mentioned as a vector for this attack, and it is possible that other parameters are also vulnerable.
Recommendations For Analysis Console for Intrusion Databases (ACID) version 0.9.6b20, consider restricting access to the acid qry main.php script until a patch is available. For Basic Analysis and Security Engine (BASE) version 1.2, consider restricting access to the base qry main.php script until a patch is available. Avoid using the sig[1] parameter in the affected API endpoints until the issue is resolved.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-3325
DSA-893-1

Affected Products

Acid
Base