Vulnerabilities > Working Resources INC

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0595 Remote Buffer Overflow vulnerability in Working Resources Inc. Badblue 2.55
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.
network
low complexity
working-resources-inc
7.5
2004-12-31 CVE-2004-2374 Path Disclosure vulnerability in Working Resources Inc. Badblue 2.40
BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML.
network
low complexity
working-resources-inc
5.0
2004-08-20 CVE-2004-1727 Denial Of Service vulnerability in Working Resources Inc. Badblue 2.50
BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.
network
low complexity
working-resources-inc
5.0
2003-06-09 CVE-2003-0332 Security Bypass vulnerability in BadBlue
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.
network
high complexity
working-resources-inc
7.6
2003-03-31 CVE-2002-1541 Unspecified vulnerability in Working Resources Inc. Badblue 1.7.0
BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).
network
low complexity
working-resources-inc
7.5
2002-12-31 CVE-2002-2289 Information Exposure vulnerability in Working Resources Inc. Badblue 1.7.1
soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.
network
low complexity
working-resources-inc CWE-200
5.0
2002-12-31 CVE-2002-2170 Unspecified vulnerability in Working Resources Inc. Badblue
Working Resources Inc.
network
low complexity
working-resources-inc
7.5
2002-12-31 CVE-2002-1685 Cross-Site Scripting vulnerability in Working Resources Inc. Badblue Enterprise1.7.2/Personal1.7/Personal1.7.2
Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.
4.3
2002-12-31 CVE-2002-1684 Directory Traversal vulnerability in Working Resources BadBlue
Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents.
network
low complexity
deerfield working-resources-inc
5.0
2002-12-31 CVE-2002-1683 Cross-Site Scripting vulnerability in Working Resources Inc. Badblue Personal1.7.3
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.
4.3