HIGH
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension
Published May 22, 2003
7.6
HIGHCVSS 2.0
EPSS 6.98%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.