20030520 BadBlue Remote Administrative Interface Access Vulnerabilitymailing list
http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0075.html CVE-2003-0332
Working Resources BadBlue 1.7.x/2.x - Unauthorized HTS Access
Record summary
CVE-2003-0332 has a selected CVSS score of 7.6; EIP currently links 1 catalogued exploit.
Description
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWorking Resources BadBlue 1.7.x/2.x - Unauthorized HTS AccessExploitDB exploitby mattmurphyNot analyzed1 file
References
320030520 BadBlue Remote Administrative Interface Access Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=105346382524169&w=2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0332