Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Badblue HIGH 7.5
CVE-2005-0595EPSS 60%

Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.

Patch available
Fix from $1,950 2005-05-02
Badblue MEDIUM 5.0
CVE-2004-2374

BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname…

No fix yet
Fix from $1,600 2004-12-31
Badblue MEDIUM 5.0
CVE-2004-1727

BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.

No fix yet
Fix from $1,600 2004-08-20
Badblue HIGH 7.6
CVE-2003-0332EPSS 7%

The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performin…

Fix: after 2.2
Fix from $1,950 2003-06-09
Badblue HIGH 7.5
CVE-2002-1541

BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).

Mitigation only
Fix from $1,950 2003-03-31
Badblue HIGH 7.5
CVE-2002-2170

Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, bu…

No fix yet
Fix from $1,950 2002-12-31
Badblue MEDIUM 5.0
CVE-2002-2289

soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.

No fix yet
Fix from $1,600 2002-12-31
Badblue HIGH 7.5
CVE-2002-1022

BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges.

No fix yet
Fix from $1,950 2002-10-04
Badblue MEDIUM 5.0
CVE-2002-1021

BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.

No fix yet
Fix from $1,600 2002-10-04
Badblue MEDIUM 5.0
CVE-2002-1023

BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.

No fix yet
Fix from $1,600 2002-10-04
Badblue MEDIUM 5.0
CVE-2002-0800

BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end.

Patch available
Fix from $1,600 2002-08-12
Badblue HIGH 7.5
CVE-2002-0326

Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands …

Patch available
Fix from $1,950 2002-06-25
Badblue MEDIUM 5.0
CVE-2002-0325EPSS 38%

Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL.

Patch available
Fix from $1,600 2002-06-25
Badblue MEDIUM 5.0
CVE-2001-1140

BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request.

Mitigation only
Fix from $1,600 2001-08-22
Badblue HIGH 10.0
CVE-2001-0277EPSS 11%

Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary co…

Patch available
Fix from $1,950 2001-05-03
Badblue MEDIUM 6.4
CVE-2001-0276

ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.d…

Patch available
Fix from $1,600 2001-05-03