peter bassill · operator
$ cve CVE-2001-0276 JSON

CVE-2001-0276 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 3.5% (pctl 89)

Patch early

A public exploit exists.

Description

ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:P
EPSS3.47% — more likely to be exploited than 89% of all CVEs
On CISA KEVno
Public exploityes
Published2001-05-03
Last modified2026-06-16

Affected (1)

VendorProduct
working resources inc.badblue

Public exploits

SourceTitleDate
exploit-dbWorking Resources BadBlue 1.2.7 - Full Path Disclosure2001-02-20

References

→ the Explorer  ·  watch your stack  ·  NVD