PT-2012-3125 · Base · Basic Analysis/Security Engine
Published
2012-02-18
·
Updated
2017-08-29
·
CVE-2012-1198
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Basic Analysis and Security Engine (BASE) version 1.4.5
Description
The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a create action, and then accessing it via a view action. This is made possible through the
base ag main.php file in the affected software.Recommendations
For Basic Analysis and Security Engine (BASE) version 1.4.5, consider restricting access to the
base ag main.php file to prevent remote attackers from uploading and executing arbitrary code until a patch is available. As a temporary workaround, avoid using the create and view actions in base ag main.php to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Basic Analysis/Security Engine