Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Badblue MEDIUM 5.0
CVE-2004-2374

BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname…

No fix yet
Fix from $1,600 2004-12-31
Badblue MEDIUM 5.0
CVE-2004-1727

BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.

No fix yet
Fix from $1,600 2004-08-20
Badblue HIGH 7.5
CVE-2002-1541

BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).

Mitigation only
Fix from $1,950 2003-03-31
Badblue HIGH 7.5
CVE-2002-2170

Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, bu…

No fix yet
Fix from $1,950 2002-12-31
Badblue MEDIUM 5.0
CVE-2002-2289

soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.

No fix yet
Fix from $1,600 2002-12-31
Badblue HIGH 7.5
CVE-2002-1022

BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges.

No fix yet
Fix from $1,950 2002-10-04
Badblue MEDIUM 5.0
CVE-2002-1021

BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.

No fix yet
Fix from $1,600 2002-10-04
Badblue MEDIUM 5.0
CVE-2002-1023

BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.

No fix yet
Fix from $1,600 2002-10-04
Badblue MEDIUM 5.0
CVE-2001-1140

BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request.

Mitigation only
Fix from $1,600 2001-08-22