Multiple Vulnerabilities In Bad Blue Web Server

Multiple Vulnerabilities have been found in Bad Blue Web Server.

Steve Manzuik

February 16, 2001

1 Min Read
ITPro Today logo

Reported February 17, 2001, by Win2KSecAdvice.

VERSIONS AFFECTED

  • BadBlue Web Server

DESCRIPTION

Multiple vulnerabilities have been discovered inBadBlue Web Server. The first issue is a directory disclosurevulnerability, where a malicious user can discover the physical path of the Webserver files. Using the URL http://webserver.com/ext.dll returns themessage "Error opening C:webserverpathdefault.htx." The secondissue is a Denial of Service (DoS) attack, where a malicious user can simplyinsert a data string of 284 bytes or more in the URL, causing the Web server tostop responding.

VENDOR RESPONSE

The vendor, Working Resource, Inc., has releaseda new version to address this issue.

CREDIT
Discovered by Strumf Noir.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like