CVE-2004-2374: Medium severity Working Resources Inc. BadBlue vulnerability
Published Dec 31, 2004
·Updated
BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML.
Affected Software
1 affected component
Working Resources Inc. BadBlue=2.40
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2374?
CVE-2004-2374 is considered to be a moderate severity vulnerability.
2
How do I fix CVE-2004-2374?
To mitigate CVE-2004-2374, ensure that BadBlue 2.4 is upgraded to a non-vulnerable version.
3
What does CVE-2004-2374 allow attackers to do?
CVE-2004-2374 allows remote attackers to reveal the server installation path by accessing phptest.php.
4
Which version of BadBlue is affected by CVE-2004-2374?
CVE-2004-2374 specifically affects BadBlue version 2.40.
5
Is there a way to prevent exploitation of CVE-2004-2374?
Preventing the exploitation of CVE-2004-2374 can be achieved by restricting access to sensitive scripts and updating the software.