PT-2003-1536 · Badblue · Badblue
Matt Murphy
·
Published
2003-05-22
·
Updated
2016-10-18
·
CVE-2003-0332
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
BadBlue versions 1.7 through 2.2
Description:
The issue allows remote attackers to bypass authentication by manipulating filename extensions. This is achieved by exploiting the ISAPI extension's behavior of modifying the first two letters of a filename extension after performing a security check. For example, using a filename with a
.ats extension instead of a .hts extension can bypass the security measures.Recommendations:
For BadBlue versions 1.7 through 2.2, consider restricting access to sensitive files and directories to minimize the risk of exploitation until a proper fix is applied. As a temporary workaround, avoid using the
.ats extension for sensitive files.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Badblue