VulnerabilityModified
CVE-2006-1505
base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to "yes".
MEDIUM 5.0EPSS 1.70%
Does this matter?
Lower severity and a low EPSS score (1.70%). Track it; it rarely justifies an emergency change on its own.
Description
base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to "yes".
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Affected
- basic analysis and security engine/base
- Source
- cve@mitre.org
References
- http://cvs.sourceforge.net/viewcvs.py/secureideas/base-php4/docs/CHANGELOG?rev=1.233&view=markup
- http://secunia.com/advisories/19510
- http://www.osvdb.org/24101Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/17354
- http://www.vupen.com/english/advisories/2006/1192
- http://cvs.sourceforge.net/viewcvs.py/secureideas/base-php4/docs/CHANGELOG?rev=1.233&view=markup
- http://secunia.com/advisories/19510
- http://www.osvdb.org/24101Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/17354
- http://www.vupen.com/english/advisories/2006/1192
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.