Record summary

CVE-2003-0332 has a selected CVSS score of 7.6; EIP currently links 1 catalogued exploit.

Description

The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWorking Resources BadBlue 1.7.x/2.x - Unauthorized HTS AccessExploitDB exploitby mattmurphyNot analyzed1 file
ExploitDB

PoC details

References

3