CVE-2003-0332

BadBlue < 2.2 - Unauthenticated Authentication Bypass via .ats Extension

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-0332. PoCs published by mattmurphy.

AI-analyzed exploit summary The exploit describes a path traversal and security bypass vulnerability in BadBlue, allowing unauthorized access to administrative functions by manipulating file extensions to '.hts'. The provided URL example demonstrates how to reveal the contents of the server's primary volume.

Description

The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.

Exploits (1)

exploitdb WRITEUP VERIFIED
by mattmurphy · textremotewindows
https://www.exploit-db.com/exploits/22620

The exploit describes a path traversal and security bypass vulnerability in BadBlue, allowing unauthorized access to administrative functions by manipulating file extensions to '.hts'. The provided URL example demonstrates how to reveal the contents of the server's primary volume.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: BadBlue (version not specified)
No auth needed
Prerequisites: Network access to the target BadBlue server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=105346382524169&w=2
Exploit, Patch, Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0075.html

Scores

EPSS 0.0698
EPSS Percentile 93.3%

Details

Status published
Products (1)
working_resources_inc./badblue < 2.2
Published Jun 09, 2003
Tracked Since Feb 18, 2026