7.6
CVSSv2

CVE-2003-0332

Published: 09/06/2003 Updated: 18/10/2016
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 765
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

The ISAPI extension in BadBlue 1.7 up to and including 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote malicious users to bypass authentication via a filename with a .ats extension instead of a .hts extension.

Vulnerable Product Search on Vulmon Subscribe to Product

working resources inc. badblue

Exploits

source: wwwsecurityfocuscom/bid/7638/info BadBlue is prone to a vulnerability that could allow remote attackers to gain unauthorized access to administrative functions It is possible to bypass BadBlue security checks when 'hts' files are requested by a remote user BadBlue restricts access to non-HTML files by replacing the first two l ...