BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://securityreason.com/securityalert/3448 | third party advisory |
http://secunia.com/advisories/28031 | third party advisory vendor advisory |
http://osvdb.org/42418 | vdb entry |
http://www.securityfocus.com/bid/26803 | vdb entry |
http://www.securityfocus.com/archive/1/484834/100/0/threaded | mailing list |
http://aluigi.altervista.org/adv/badblue-adv.txt | exploit |
http://www.vupen.com/english/advisories/2007/4160 | vdb entry |