base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to "yes".
| Software | From | Fixed in |
|---|---|---|
| basic_analysis_and_security_engine / base | 1.1_elizabeth | 1.1_elizabeth.x |
| basic_analysis_and_security_engine / base | 1.2.2_cindy | 1.2.2_cindy.x |
| basic_analysis_and_security_engine / base | 1.1.3_lynn | 1.1.3_lynn.x |
| basic_analysis_and_security_engine / base | 1.1.4_cheryl | 1.1.4_cheryl.x |
| basic_analysis_and_security_engine / base | 1.2.1_kris | 1.2.1_kris.x |
| basic_analysis_and_security_engine / base | 1.2_betty | 1.2_betty.x |
| basic_analysis_and_security_engine / base | 1.1.2_zora | 1.1.2_zora.x |