6.4
CVSSv2

CVE-2001-0276

Published: 03/05/2001 Updated: 10/10/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote malicious users to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.

Vulnerable Product Search on Vulmon Subscribe to Product

working resources inc. badblue 1.2.7

Exploits

source: wwwsecurityfocuscom/bid/2390/info Requesting a specially crafted URL to a machine running Working Resources BadBlue, will disclose the physical path to the root directory target/extdll will result in: [Error: opening c:\program files\badblue\pe\defaulthtx (2)] ...