PT-2003-1274 · Badblue · Badblue
Published
2003-03-31
·
Updated
2008-09-05
·
CVE-2002-1541
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BadBlue version 1.7
Description
The issue allows remote attackers to bypass password protections for directories and files by sending an HTTP request with an extra / (slash).
Recommendations
For BadBlue version 1.7, consider restricting access to sensitive directories and files as a temporary workaround until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Badblue