---
title: "CVE-2012-1199\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-1199?format=md
keywords: index, follow
---

# CVE-2012-1199

Publication date 18 February 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and
Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary
PHP code via a URL in the (1) BASE\_path parameter to base\_ag\_main.php, (2)
base\_db\_setup.php, (3) base\_graph\_common.php, (4) base\_graph\_display.php,
(5) base\_graph\_form.php, (6) base\_graph\_main.php, (7) base\_local\_rules.php,
(8) base\_logout.php, (9) base\_main.php, (10) base\_maintenance.php, (11)
base\_payload.php, (12) base\_qry\_alert.php, (13) base\_qry\_common.php, (14)
base\_qry\_main.php, (15) base\_stat\_alerts.php, (16) base\_stat\_class.php,
(17) base\_stat\_common.php, (18) base\_stat\_ipaddr.php, (19)
base\_stat\_iplink.php, (20) base\_stat\_ports.php, (21) base\_stat\_sensor.php,
(22) base\_stat\_time.php, (23) base\_stat\_uaddr.php, (24) base\_user.php, (25)
index.php, (26) admin/base\_roleadmin.php, (27) admin/base\_useradmin.php,
(28) admin/index.php, (29) help/base\_setup\_help.php, (30)
includes/base\_action.inc.php, (31) includes/base\_cache.inc.php, (32)
includes/base\_db.inc.php, (33) includes/base\_db.inc.php, (34)
includes/base\_include.inc.php, (35) includes/base\_output\_html.inc.php, (36)
includes/base\_output\_query.inc.php, (37)
includes/base\_state\_criteria.inc.php, (38)
includes/base\_state\_query.inc.php or (39) setup/base\_conf\_contents.php;
(40) GLOBALS[user\_session\_path] parameter to
includes/base\_state\_common.inc.php; (41) BASE\_Language parameter to
setup/base\_conf\_contents.php; or (42) ado\_inc\_php parameter to
setup/setup2.php.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| acidbase | 17.04 zesty | Not in release |
| 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 15.10 wily | Not in release |
| 15.04 vivid | Not in release |
| 14.10 utopic | Not in release |
| 14.04 LTS trusty | Not in release |
| 13.10 saucy | Not in release |
| 13.04 raring | Ignored end of life |
| 12.10 quantal | Ignored end of life |
| 12.04 LTS precise | Ignored end of life |
| 11.10 oneiric | Ignored end of life |
| 11.04 natty | Ignored end of life |
| 10.10 maverick | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1199)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-1199)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-1199)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-1199)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2012-1199>
