Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://online.securityfocus.com/archive/1/283418 - | |
References | () http://www.iss.net/security_center/static/9642.php - | |
References | () http://www.securityfocus.com/bid/5276 - Exploit |
Information
Published : 2002-12-31 05:00
Updated : 2024-11-20 23:43
NVD link : CVE-2002-2170
Mitre link : CVE-2002-2170
CVE.ORG link : CVE-2002-2170
JSON object : View
Products Affected
working_resources_inc.
- badblue
CWE