PT-2005-4135 · Acid+1 · Acid+1
Remco Verhoef
·
Published
2005-10-27
·
Updated
2012-07-03
·
CVE-2005-3325
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Analysis Console for Intrusion Databases (ACID) version 0.9.6b20
Basic Analysis and Security Engine (BASE) version 1.2
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through SQL injection vulnerabilities in certain console scripts, including acid qry main.php in ACID and base qry main.php in BASE. The
sig[1] parameter is specifically mentioned as a vector for this attack, and it is possible that other parameters are also vulnerable.Recommendations
For Analysis Console for Intrusion Databases (ACID) version 0.9.6b20, consider restricting access to the
acid qry main.php script until a patch is available.
For Basic Analysis and Security Engine (BASE) version 1.2, consider restricting access to the base qry main.php script until a patch is available.
Avoid using the sig[1] parameter in the affected API endpoints until the issue is resolved.Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acid
Base