{ "schema_version": "1.4.0", "id": "GHSA-qvvm-q759-c698", "modified": "2022-05-02T03:58:43Z", "published": "2022-05-02T03:58:43Z", "aliases": [ "CVE-2009-4837" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sig[1] parameter to base/base_qry_main.php, or the time[0][1] parameter to (2) base/base_stat_alerts.php or (3) base/base_stat_uaddr.php. NOTE: some of these details are obtained from third party information.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-4837" }, { "type": "WEB", "url": "http://base.secureideas.net/news.php" }, { "type": "WEB", "url": "http://secunia.com/advisories/35222" }, { "type": "WEB", "url": "http://secureideas.cvs.sourceforge.net/viewvc/secureideas/base-php4/base_ag_common.php?sortby=date&view" }, { "type": "WEB", "url": "http://spl0it.org/files/BASE-XSS/Reflective-notes.txt" } ], "database_specific": { "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2010-05-06T12:47:00Z" } }