Multiple Vulnerabilities In Bad Blue Web Server
Multiple Vulnerabilities have been found in Bad Blue Web Server.
February 16, 2001
Reported February 17, 2001, by Win2KSecAdvice.
VERSIONS AFFECTED
BadBlue Web Server
DESCRIPTION
Multiple vulnerabilities have been discovered inBadBlue Web Server. The first issue is a directory disclosurevulnerability, where a malicious user can discover the physical path of the Webserver files. Using the URL http://webserver.com/ext.dll returns themessage "Error opening C:webserverpathdefault.htx." The secondissue is a Denial of Service (DoS) attack, where a malicious user can simplyinsert a data string of 284 bytes or more in the URL, causing the Web server tostop responding.
VENDOR RESPONSE
The vendor, Working Resource, Inc., has releaseda new version to address this issue.
CREDIT
Discovered by Strumf Noir.
About the Author
You May Also Like