CVE-2001-1140: Medium severity Working Resources Inc. BadBlue vulnerability
Published Aug 22, 2001
·Updated
BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request.
Affected Software
1 affected component
Working Resources Inc. BadBlue=1.02_beta
Event History
Aug 22, 2001
CVE Published
04:00 AM
Mar 15, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1140?
CVE-2001-1140 has been classified as a low severity vulnerability.
2
How do I fix CVE-2001-1140?
To fix CVE-2001-1140, upgrade your BadBlue Personal Edition to a version that does not allow null byte injection.
3
What type of attacks does CVE-2001-1140 enable?
CVE-2001-1140 enables remote attackers to read the source code of executable programs.
4
Which software is affected by CVE-2001-1140?
CVE-2001-1140 specifically affects BadBlue Personal Edition version 1.02 beta.
5
What is a null byte in the context of CVE-2001-1140?
In the context of CVE-2001-1140, a null byte is a character used in URL requests that can manipulate the server into revealing code.