Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Matt Murphy

#20304of 53,634
12.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2003-1536
7.6
2003-05-22
Badblue · Badblue · CVE-2003-0332
Name of the Vulnerable Software and Affected Versions: BadBlue versions 1.7 through 2.2 Description: The issue allows remote attackers to bypass authentication by manipulating filename extensions. This is achieved by exploiting the ISAPI extension's behavior of modifying the first two letters of a filename extension after performing a security check. For example, using a filename with a `.ats` extension instead of a `.hts` extension can bypass the security measures. Recommendations: For BadBlue versions 1.7 through 2.2, consider restricting access to sensitive files and directories to minimize the risk of exploitation until a proper fix is applied. As a temporary workaround, avoid using the `.ats` extension for sensitive files.
PT-2003-1497
5.0
2003-05-14
Eserv · Eserv · CVE-2003-0290
Name of the Vulnerable Software and Affected Versions: eServ versions 2.9x Description: A memory leak in the software allows remote attackers to cause a denial of service, specifically memory exhaustion, by establishing a large number of connections. The memory allocated for these connections is not freed when the connections are terminated. Recommendations: For eServ versions 2.9x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.