Working Resources BadBlue Directory Contents Disclosure Vulnerability
BID:4912
Info
Working Resources BadBlue Directory Contents Disclosure Vulnerability
| Bugtraq ID: | 4912 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0800 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Credited to "a b" <[email protected]>. |
| Vulnerable: |
Working Resources Inc. BadBlue 1.7 .0 |
| Not Vulnerable: |
Working Resources Inc. BadBlue 1.7.1 |
Discussion
Working Resources BadBlue Directory Contents Disclosure Vulnerability
Working Resources BadBlue is a webserver intended to share various resources and is developed for Microsoft Windows environments. By default BadBlue prevents users from viewing the contents of directories.
If a remote user appends the unicode variant of the "%" symbol, it will cause the web server to display the contents of the current directory.
Working Resources BadBlue is a webserver intended to share various resources and is developed for Microsoft Windows environments. By default BadBlue prevents users from viewing the contents of directories.
If a remote user appends the unicode variant of the "%" symbol, it will cause the web server to display the contents of the current directory.
Exploit / POC
Working Resources BadBlue Directory Contents Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Working Resources BadBlue Directory Contents Disclosure Vulnerability
Solution:
The vendor has issued a fix.
Working Resources Inc. BadBlue 1.7 .0
Solution:
The vendor has issued a fix.
Working Resources Inc. BadBlue 1.7 .0
-
Working Resources Inc. bb95.exe
For Windows 95 and NT.
http://www.badblue.com/bb95.exe -
Working Resources Inc. bb98.exe
For Windows 98, Me, 2000, and Windows XP.
http://www.badblue.com/bb98.exe