CVE-2001-0276 EXPLOIT
6.4
MEDIUM · CVSS 2.0 · EPSS 3.5% (pctl 89)
Patch early
A public exploit exists.
Description
ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.
Scoring
| CVSS | 6.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:P |
| EPSS | 3.47% — more likely to be exploited than 89% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-05-03 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| working resources inc. | badblue |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Working Resources BadBlue 1.2.7 - Full Path Disclosure | 2001-02-20 |
References
- http://marc.info/?l=bugtraq&m=98263019502565&w=2
- http://www.badblue.com/p010219.htm
- http://www.securityfocus.com/bid/2390
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6130
- http://marc.info/?l=bugtraq&m=98263019502565&w=2
- http://www.badblue.com/p010219.htm
- http://www.securityfocus.com/bid/2390
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6130
→ the Explorer · watch your stack · NVD