Description
Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Matthew Murphy · cremotewindows
https://www.exploit-db.com/exploits/21601
References (8)
Scores
EPSS
0.6023
EPSS Percentile
98.3%
Details
Status
published
Products (2)
microsoft/foundation_class_library
7.0
working_resources_inc./badblue
personal_1.7.3
Published
Dec 31, 2002
Tracked Since
Feb 18, 2026