CVE-2003-0332
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.
Scoring
- CVSS base score
- 0.08
- EPSS probability
- 1.98%
- Published
- 2003-05-22
- Last modified
- 2026-03-16
Affected products
- n/a n/a