CVE-2003-0332
BadBlue < 2.2 - Unauthenticated Authentication Bypass via .ats Extension
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2003-0332. PoCs published by mattmurphy.
AI-analyzed exploit summary The exploit describes a path traversal and security bypass vulnerability in BadBlue, allowing unauthorized access to administrative functions by manipulating file extensions to '.hts'. The provided URL example demonstrates how to reveal the contents of the server's primary volume.
Description
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.
Exploits (1)
The exploit describes a path traversal and security bypass vulnerability in BadBlue, allowing unauthorized access to administrative functions by manipulating file extensions to '.hts'. The provided URL example demonstrates how to reveal the contents of the server's primary volume.