Working Resources BadBlue Cross Site Scripting Vulnerability
BID:4180
Info
Working Resources BadBlue Cross Site Scripting Vulnerability
| Bugtraq ID: | 4180 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0326 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Discovered by Strumpf Noir Society <[email protected]>. |
| Vulnerable: |
Working Resources Inc. BadBlue Enterprise Edition 1.5 Working Resources Inc. BadBlue 1.6.1 beta Working Resources Inc. BadBlue 1.5.6 beta Working Resources Inc. BadBlue 1.5 Working Resources Inc. BadBlue 1.2.8 Working Resources Inc. BadBlue 1.2.7 Deerfield D2Gfx 1.0.2 |
| Not Vulnerable: | |
Discussion
Working Resources BadBlue Cross Site Scripting Vulnerability
Working Resources BadBlue is a webserver intended to share various resources and is developed for Microsoft Windows environments. Shared files specifically, are served through a library called 'ext.dll'. BadBlue also acts as a Gnutella client, it is administrated and used through a web interface to the local BadBlue web server.
It has been reported that BadBlue suffers from multiple cross site scripting vulnerabilities. Execution of script code may allow administrative access to the BadBlue server, as any local user is assumed to be an administrator.
Working Resources BadBlue is a webserver intended to share various resources and is developed for Microsoft Windows environments. Shared files specifically, are served through a library called 'ext.dll'. BadBlue also acts as a Gnutella client, it is administrated and used through a web interface to the local BadBlue web server.
It has been reported that BadBlue suffers from multiple cross site scripting vulnerabilities. Execution of script code may allow administrative access to the BadBlue server, as any local user is assumed to be an administrator.
Exploit / POC
Working Resources BadBlue Cross Site Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Working Resources BadBlue Cross Site Scripting Vulnerability
Solution:
Reports state that version 1.6.1 beta of BadBlue resolves some, but not all of the cross site scripting issues.
If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Reports state that version 1.6.1 beta of BadBlue resolves some, but not all of the cross site scripting issues.
If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Working Resources BadBlue Cross Site Scripting Vulnerability
References:
References:
- BadBlue Product Homepage (Working Resources Inc)
- D2Ggx Homepage (Deerfield)