Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Working Resources BadBlue NULL字节远程文件泄露漏洞
Vulnerability Description
BadBlue是一款由Working Resources开发的P2P文件共享应用程序,可使用在Microsoft Windows操作系统下。 BadBlue对用户提交的包含NULL字符的HTTP请求缺少正确的处理,远程攻击者可以利用这个漏洞以BadBlue进程权限查看系统上文件内容。 通过发送包含URL编码的NULL字节("%00")请求给BadBlue,BadBlue会返回包含请求文件的源代码信息,此漏洞可以用来读取存储BadBlue配置信息的EXT.INI文件,攻击者可以简单的在文件名EXT.INI后
CVSS Information
N/A
Vulnerability Type
N/A