Working Resources BadBlue Unauthorized Proxy Relay Vulnerability
BID:11030
Info
Working Resources BadBlue Unauthorized Proxy Relay Vulnerability
| Bugtraq ID: | 11030 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2002 12:00AM |
| Updated: | Dec 11 2002 12:00AM |
| Credit: | Discovery is credited to Texonet. |
| Vulnerable: |
Working Resources Inc. BadBlue Personal Edition 2.16 Working Resources Inc. BadBlue Personal Edition 2.15 Working Resources Inc. BadBlue Personal Edition 2.5 Working Resources Inc. BadBlue Personal Edition 2.4 Working Resources Inc. BadBlue Personal Edition 2.3 Working Resources Inc. BadBlue Personal Edition 2.2 Working Resources Inc. BadBlue Personal Edition 2.1 Working Resources Inc. BadBlue Personal Edition 2.0 Working Resources Inc. BadBlue Personal Edition 1.7.4 Working Resources Inc. BadBlue Personal Edition 1.7.3 Working Resources Inc. BadBlue Personal Edition 1.7.2 Working Resources Inc. BadBlue Personal Edition 1.7 Working Resources Inc. BadBlue Personal Edition 1.6 Beta Working Resources Inc. BadBlue Personal Edition 1.5.6 Beta |
| Not Vulnerable: | |
Discussion
Working Resources BadBlue Unauthorized Proxy Relay Vulnerability
BadBlue is prone to a vulnerability that may let the application be abused as a proxy. This vulnerability presents itself due to the 'Pass Thru' function allowing the server to be used as a proxy. This could be exploited by malicious parties to obfuscate their identities and bypass network access controls and firewalls.
BadBlue Personal Edition versions 2.5 and prior are reportedly affected by this issue.
BadBlue is prone to a vulnerability that may let the application be abused as a proxy. This vulnerability presents itself due to the 'Pass Thru' function allowing the server to be used as a proxy. This could be exploited by malicious parties to obfuscate their identities and bypass network access controls and firewalls.
BadBlue Personal Edition versions 2.5 and prior are reportedly affected by this issue.
Exploit / POC
Working Resources BadBlue Unauthorized Proxy Relay Vulnerability
This issue can be exploited with a Web browser.
The following proof of concept is available:
http://www.example.com/ext.dll?mfcisapicommand=PassThru&url=[Any IP:Any Port]/[Any Command]
This issue can be exploited with a Web browser.
The following proof of concept is available:
http://www.example.com/ext.dll?mfcisapicommand=PassThru&url=[Any IP:Any Port]/[Any Command]
Solution / Fix
Working Resources BadBlue Unauthorized Proxy Relay Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Working Resources BadBlue Unauthorized Proxy Relay Vulnerability
References:
References:
- BadBlue Unauthorized Proxy Vulnerability (iDEFENSE)