20010217 BadBlue Web Server Ext.dll Vulnerabilitiesmailing list
http://marc.info/?l=bugtraq&m=98263019502565&w=2 CVE-2001-0276
Working Resources BadBlue 1.2.7 - Full Path Disclosure
Record summary
CVE-2001-0276 has a selected CVSS score of 6.4; EIP currently links 1 catalogued exploit.
Description
ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWorking Resources BadBlue 1.2.7 - Full Path DisclosureExploitDB exploitby SNS ResearchNot analyzed1 file
References
5badblue.comConfirmation
http://www.badblue.com/p010219.htm 2390vdb entry
http://www.securityfocus.com/bid/2390 badblue-ext-reveal-path(6130)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6130 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0276