<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to bugs</title><link>https://sourceforge.net/p/secureideas/bugs/</link><description>Recent changes to bugs</description><atom:link href="https://sourceforge.net/p/secureideas/bugs/feed.rss" rel="self"/><language>en</language><lastBuildDate>Fri, 03 May 2013 19:23:27 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/secureideas/bugs/feed.rss" rel="self" type="application/rss+xml"/><item><title>Issue BASE autentication with Oracle 11g</title><link>https://sourceforge.net/p/secureideas/bugs/247/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;First I want congrat you for your excepcional work with BASE.&lt;br /&gt;
Second I am deploying Base with Oracle 11g and I am with issue in autentication.&lt;br /&gt;
All function works fine, but autentication don´t work.&lt;br /&gt;
Base can create the user and password but when I enable autentication don´t work.&lt;br /&gt;
Application returns as "user don´t exist or password was wrong".&lt;br /&gt;
If you could help me, I will stay very thankful.&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Paulo Matos</dc:creator><pubDate>Fri, 03 May 2013 19:23:27 -0000</pubDate><guid>https://sourceforge.net0d93fa73c6281e76c3d048b9083bcf7fee6d83b7</guid></item><item><title>Issue BASE autentication with Oracle</title><link>https://sourceforge.net/p/secureideas/bugs/246/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;First I want congrat you for your excepcional work with BASE.&lt;br /&gt;
Second I am deploying  Base with Oracle 11g and I am with issue in autentication.&lt;br /&gt;
All function works fine, but autentication don´t work.&lt;br /&gt;
Base can create the user and password but when I enable autentication don´t work.&lt;br /&gt;
Application returns as "user don´t exist or password was wrong".&lt;br /&gt;
If you could help me, I will stay very thankful.&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Fri, 03 May 2013 15:55:29 -0000</pubDate><guid>https://sourceforge.net159a36c3eef3d8c25f323f3c58b66df8afe54e0a</guid></item><item><title>PHP Remote Inclusion Vulnerability</title><link>https://sourceforge.net/p/secureideas/bugs/245/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;we ran some tests on one of our installations and found an remote inclusion vulnerability as already published on:&lt;br /&gt;
&lt;a href="http://xforce.iss.net/xforce/xfdb/73200" rel="nofollow"&gt;http://xforce.iss.net/xforce/xfdb/73200&lt;/a&gt;&lt;br /&gt;
and&lt;br /&gt;
&lt;a href="http://packetstormsecurity.com/files/109663/BASE-1.4.5-Remote-File-Inclusion-Shell-Creation.html" rel="nofollow"&gt;http://packetstormsecurity.com/files/109663/BASE-1.4.5-Remote-File-Inclusion-Shell-Creation.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Do you plan on fixing these issues?&lt;/p&gt;
&lt;p&gt;Kind regards.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Fri, 26 Apr 2013 17:10:18 -0000</pubDate><guid>https://sourceforge.net3af4ca8a0bf44ed534a312e362562a4aff01a341</guid></item><item><title>2995737 patch</title><link>https://sourceforge.net/p/secureideas/bugs/244/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Fix Sensor.name sort in base_sensor_stat.php&lt;/p&gt;
&lt;p&gt;Props to abenson&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Fri, 25 Mar 2011 16:03:07 -0000</pubDate><guid>https://sourceforge.net33f21041484d4dfdce0694ecf09af96d32f5e532</guid></item><item><title>error in DB connection settings</title><link>https://sourceforge.net/p/secureideas/bugs/243/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;BASE doesn't show any data until in base_conf.php will be set $alert_host='0.0.0.0' and $archive_host='localhost'. In other variations of this parameters (both set to localhost, or to 0.0.0.0) BASE didn't work.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Wed, 09 Mar 2011 13:06:47 -0000</pubDate><guid>https://sourceforge.net2eed2751cce4a4afeb5c6d69749c175f3f5822a0</guid></item><item><title>Bug in Base 1.4.5</title><link>https://sourceforge.net/p/secureideas/bugs/242/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi not sure if this is the way to submit a bug.  I am using BASE and ADODB with Oracle as a backend DB.  When I tried to use Base 1.4.5 I found that the lower part of the main BASE page (base_main.php) threw an Oracle error for the lower part of the screen (which remains blank).  The error was "Database ERROR: Database ERROR: ORA-00907 missing parenthesis".  When I ripped out Base 1.4.5 and went back to 1.4.3 the error was not occurring.  Thanks.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Gilbert Standen</dc:creator><pubDate>Fri, 24 Sep 2010 22:51:31 -0000</pubDate><guid>https://sourceforge.net0368d0e47a092db595f2860ab213a24b7e99c462</guid></item><item><title>XSS</title><link>https://sourceforge.net/p/secureideas/bugs/241/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Base has a XSS bug in search field.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Wed, 11 Aug 2010 07:24:07 -0000</pubDate><guid>https://sourceforge.net909221d985756938c23752d2cfad36175c693381</guid></item><item><title>Sagan SID's show up as Emerging Thread SIDS.</title><link>https://sourceforge.net/p/secureideas/bugs/240/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Sagan is a real time log analysis tool that can store and correlate IDS/IPS information with log information.  For more information,  please see &lt;a href="http://sagan.softwink.com." rel="nofollow"&gt;http://sagan.softwink.com.&lt;/a&gt;   Sagan uses the Snort MySQL and PostgreSQL to store events and for correlation.  When Sagan stores events,  reference URLs show Sagan alerts as "EmThreat",  which is incorrect.   Sagan rule set SID's start at 500000.  It's likely that BASE simply considers EmThreat rules any thing over 200000 (?).   There's a screen shot of this issue at: &lt;a href="http://sagan.softwink.com/screenshots.html" rel="nofollow"&gt;http://sagan.softwink.com/screenshots.html&lt;/a&gt; (about middle of the page).   Let me know if you need any more information.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Da Beave</dc:creator><pubDate>Thu, 22 Jul 2010 14:40:38 -0000</pubDate><guid>https://sourceforge.net125247ef988783629bacadcb9fc31a7fe2921bd3</guid></item><item><title>Sorting order</title><link>https://sourceforge.net/p/secureideas/bugs/239/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;base 1.4.5&lt;/p&gt;
&lt;p&gt;base_stat_sensor.php:                         " ORDER BY sensor.name ASC",&lt;br /&gt;
base_stat_sensor.php:                         " ORDER BY sensor.name DESC");&lt;/p&gt;
&lt;p&gt;Unknown column 'sensor.name' in 'order clause'&lt;/p&gt;
&lt;p&gt;$qro-&amp;gt;AddTitle(_SIPLTOTALEVENTS,&lt;br /&gt;
"occur_a", " ",&lt;br /&gt;
" ORDER BY event_cnt ASC",&lt;br /&gt;
"occur_d", " ",&lt;br /&gt;
" ORDER BY event_cnt DESC"); &lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;"missing" -&amp;gt; " ORDER BY event_cnt ASC", and  " ORDER BY event_cnt DESC");&lt;/p&gt;
&lt;p&gt;Order by unique event not work correctly&lt;br /&gt;
$qro-&amp;gt;AddTitle(_SIPLUNIEVENTS,&lt;br /&gt;
"occur_a", "", " ORDER BY sig_cnt ASC",&lt;br /&gt;
"occur_d", "", " ORDER BY sig_cnt DESC");&lt;/p&gt;
&lt;p&gt;$sql = "SELECT DISTINCT acid_event.sid, count(acid_event.cid) as event_cnt,".&lt;br /&gt;
" count(distinct(acid_event.signature)) as sig_cnt, ".&lt;br /&gt;
" count(distinct(acid_event.ip_src)) as saddr_cnt, ".&lt;br /&gt;
" count(distinct(acid_event.ip_dst)) as daddr_cnt, ".&lt;br /&gt;
"min(timestamp) as first_timestamp, max(timestamp) as last_timestamp".&lt;br /&gt;
$sort_sql[0].$from.$where." GROUP BY acid_event.sid ".$sort_sql[1];&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Mon, 03 May 2010 06:09:46 -0000</pubDate><guid>https://sourceforge.net02642bcdbd9be198a80890a9665625964c3aa9c4</guid></item><item><title>Sorting order</title><link>https://sourceforge.net/p/secureideas/bugs/238/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;base 1.4.5&lt;/p&gt;
&lt;p&gt;base_stat_sensor.php:                         " ORDER BY sensor.name ASC",&lt;br /&gt;
base_stat_sensor.php:                         " ORDER BY sensor.name DESC");&lt;/p&gt;
&lt;p&gt;Unknown column 'sensor.name' in 'order clause'&lt;/p&gt;
&lt;p&gt;$qro-&amp;gt;AddTitle(_SIPLTOTALEVENTS,&lt;br /&gt;
"occur_a", " ",&lt;br /&gt;
" ORDER BY event_cnt ASC",&lt;br /&gt;
"occur_d", " ",&lt;br /&gt;
" ORDER BY event_cnt DESC"); &lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;"missing" -&amp;gt; " ORDER BY event_cnt ASC", and  " ORDER BY event_cnt DESC");&lt;/p&gt;
&lt;p&gt;Order by unique event not work correctly&lt;br /&gt;
$qro-&amp;gt;AddTitle(_SIPLUNIEVENTS,&lt;br /&gt;
"occur_a", "", " ORDER BY sig_cnt ASC",&lt;br /&gt;
"occur_d", "", " ORDER BY sig_cnt DESC");&lt;/p&gt;
&lt;p&gt;$sql = "SELECT DISTINCT acid_event.sid, count(acid_event.cid) as event_cnt,".&lt;br /&gt;
" count(distinct(acid_event.signature)) as sig_cnt, ".&lt;br /&gt;
" count(distinct(acid_event.ip_src)) as saddr_cnt, ".&lt;br /&gt;
" count(distinct(acid_event.ip_dst)) as daddr_cnt, ".&lt;br /&gt;
"min(timestamp) as first_timestamp, max(timestamp) as last_timestamp".&lt;br /&gt;
$sort_sql[0].$from.$where." GROUP BY acid_event.sid ".$sort_sql[1];&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Mon, 03 May 2010 04:32:13 -0000</pubDate><guid>https://sourceforge.netd857ecdfcdcbbbdfe20804ecd612b27742071cf2</guid></item></channel></rss>