- Description
- ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:P
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:working_resources_inc.:badblue:1.2.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7718A5FF-58F1-4086-8EF8-E67F5D48EB79"
}
],
"operator": "OR"
}
]
}
]