Working Resources BadBlue Double Slash Directory Access Control Circumvention Vulnerability
BID:6044
Info
Working Resources BadBlue Double Slash Directory Access Control Circumvention Vulnerability
| Bugtraq ID: | 6044 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-1541 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Vulnerability discovery credited to Tamer Sahin <[email protected]>. |
| Vulnerable: |
Working Resources Inc. BadBlue 1.7 .0 |
| Not Vulnerable: | |
Discussion
Working Resources BadBlue Double Slash Directory Access Control Circumvention Vulnerability
BadBlue is a P2P file sharing application distributed by Working Resources. It is available for Microsoft Windows operating systems.
Typically, a request made in BadBlue for a directory that has access control restrictions in place will either prompt a user for authentication credentials or deny access to the resources. However, by submitting a special request to the server, it is possible to circumvent these access control restrictions. It has been reported that domain names ending with a double slash allow this activity.
BadBlue is a P2P file sharing application distributed by Working Resources. It is available for Microsoft Windows operating systems.
Typically, a request made in BadBlue for a directory that has access control restrictions in place will either prompt a user for authentication credentials or deny access to the resources. However, by submitting a special request to the server, it is possible to circumvent these access control restrictions. It has been reported that domain names ending with a double slash allow this activity.
Exploit / POC
Working Resources BadBlue Double Slash Directory Access Control Circumvention Vulnerability
This vulnerability may be exploited with a web browser.
This vulnerability may be exploited with a web browser.
Solution / Fix
Working Resources BadBlue Double Slash Directory Access Control Circumvention Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Working Resources BadBlue Double Slash Directory Access Control Circumvention Vulnerability
References:
References:
- BadBlue Product Homepage (Working Resources Inc)