Vulnerabilities > CVE-2003-0332 - Unspecified vulnerability in Working Resources Inc. Badblue
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Working Resources BadBlue 1.7.x/2.x Unauthorized HTS Access Vulnerability. CVE-2003-0332. Remote exploit for windows platform |
id | EDB-ID:22620 |
last seen | 2016-02-02 |
modified | 2003-05-20 |
published | 2003-05-20 |
reporter | mattmurphy |
source | https://www.exploit-db.com/download/22620/ |
title | Working Resources BadBlue 1.7.x/2.x Unauthorized HTS Access Vulnerability |
Nessus
NASL family | Web Servers |
NASL id | BADBLUE_REMOTE_ADMINISTRATIVE_ACCESS.NASL |
description | The remote host is running the BadBlue web server earlier than 2.2. Such versions are reportedly affected by an authentication bypass vulnerability. It is possible for an attacker to gain administrative access using a filename with a .ats extension instead of a .hts extension. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11554 |
published | 2003-04-27 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11554 |
title | BadBlue ISAPI Extension .hts Crafted File Extension Request Authentication Bypass |
code |
|