Korean
<< Back
VID 22328
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The BadBlue server allows remote attackers to read restricted files. BadBlue is a P2P file sharing Web server distributed by Working Resources for Microsoft Windows operating systems. BadBlue Personal Edition version 1.7.3 could allow a remote attacker to obtain sensitive information by sending an invalid GET request. By sending a GET request for a known file appended with a malformed hexadecimal URL encoded NULL byte character containing a space (% 00), a remote attacker could read restricted files, such as EXT.INI (BadBlue configuration file)

* References:
http://www.securityfocus.com/archive/1/282054

* Platforms Affected:
Working Resources Inc., BadBlue Personal Edition 1.7.3
Microsoft Windows Any version
Recommendation Upgrade to the latest version of BadBlue (2.61 or later), available from the BadBlue Download Web site at http://www.badblue.com/down.htm
Related URL CVE-2002-1021,CVE-2002-1022 (CVE)
Related URL 5226,5228 (SecurityFocus)
Related URL 9557,9558 (ISS)