4.3
CVSSv2

CVE-2002-1685

Published: 31/12/2002 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote malicious users to execute arbitrary script as other users by injecting script into ext.dll ISAPI.

Vulnerable Product Search on Vulmon Subscribe to Product

working resources inc. badblue enterprise_1.7.2

working resources inc. badblue personal_1.7

working resources inc. badblue personal_1.7.2

Exploits

source: wwwsecurityfocuscom/bid/5086/info BadBlue is a P2P file sharing application distributed by Working Resources The extdll ISAPI does not sufficiently sanitize input Because of this, it is possible for a user to create a custom URL containing script code that, when viewed in a browser by another user, will result in the execution ...