Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

BadBlue Source Code Disclosure Vulnerability

BadBlue is a small web-based file sharing utility for Microsoft Windows systems.

BadBlue v1.02 does not filter some some malicious strings from web requests. A null character(%00) placed at the end of a web request for a known file(within the webroot directory tree) will cause the file to be displayed by BadBlue. If the file is a script then it's contents will be output instead of it being interpreted.







 

Privacy Statement
Copyright 2008, SecurityFocus