HIGH · 7.6

CVE-2003-0332

The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers t...

Vulnerability Description

The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.

CVSS Score

7.6

HIGH

AV:N/AC:H/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Working Resources Inc.Badblue<= 2.2

References

FAQ

What is CVE-2003-0332?

CVE-2003-0332 is a vulnerability with a CVSS score of 7.6 (HIGH). The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers t...

How severe is CVE-2003-0332?

CVE-2003-0332 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2003-0332?

Check the references section above for vendor advisories and patch information. Affected products include: Working Resources Inc. Badblue.