First published: Sat Aug 31 2002(Updated: )
BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Working Resources Inc. BadBlue | =1.7.3_personal | |
Working Resources Inc. BadBlue | =1.7.3_enterprise |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1021 is considered a moderate severity vulnerability because it allows attackers to read restricted files.
To fix CVE-2002-1021, update BadBlue server to a version subsequent to 1.7.3 that addresses this vulnerability.
CVE-2002-1021 allows remote attackers to read restricted files such as EXT.INI.
CVE-2002-1021 affects BadBlue versions 1.7.3 personal and 1.7.3 enterprise.
Yes, CVE-2002-1021 can be exploited remotely through specially crafted HTTP requests.