| VID |
22328 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
WWW |
| Detailed Description |
The BadBlue server allows remote attackers to read restricted files. BadBlue is a P2P file sharing Web server distributed by Working Resources for Microsoft Windows operating systems. BadBlue Personal Edition version 1.7.3 could allow a remote attacker to obtain sensitive information by sending an invalid GET request. By sending a GET request for a known file appended with a malformed hexadecimal URL encoded NULL byte character containing a space (% 00), a remote attacker could read restricted files, such as EXT.INI (BadBlue configuration file)
* References: http://www.securityfocus.com/archive/1/282054
* Platforms Affected: Working Resources Inc., BadBlue Personal Edition 1.7.3 Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version of BadBlue (2.61 or later), available from the BadBlue Download Web site at http://www.badblue.com/down.htm |
| Related URL |
CVE-2002-1021,CVE-2002-1022 (CVE) |
| Related URL |
5226,5228 (SecurityFocus) |
| Related URL |
9557,9558 (ISS) |
|