BadBlue Source Code Disclosure Vulnerability
BID:3222
Info
BadBlue Source Code Disclosure Vulnerability
| Bugtraq ID: | 3222 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1140 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was submitted to BugTraq on August 22nd, 2001 by "acz \[iSecureLabs\]" <[email protected]>. |
| Vulnerable: |
BadBlue BadBlue Personal Edition 1.0 2 beta |
| Not Vulnerable: |
BadBlue BadBlue Personal Edition 1.5 |
Discussion
BadBlue Source Code Disclosure Vulnerability
BadBlue is a small web-based file sharing utility for Microsoft Windows systems.
BadBlue v1.02 does not filter some some malicious strings from web requests. A null character(%00) placed at the end of a web request for a known file(within the webroot directory tree) will cause the file to be displayed by BadBlue. If the file is a script then it's contents will be output instead of it being interpreted.
BadBlue is a small web-based file sharing utility for Microsoft Windows systems.
BadBlue v1.02 does not filter some some malicious strings from web requests. A null character(%00) placed at the end of a web request for a known file(within the webroot directory tree) will cause the file to be displayed by BadBlue. If the file is a script then it's contents will be output instead of it being interpreted.
Exploit / POC
BadBlue Source Code Disclosure Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
Solution / Fix
BadBlue Source Code Disclosure Vulnerability
Solution:
Upgrade to BadBlue version 1.5 or higher.
Solution:
Upgrade to BadBlue version 1.5 or higher.