BadBlue.MFCISAPICommand.Remote.Buffer.Overflow

description-logoDescription

BadBlue is a free personal file-sharing Web server developed by Working Resources Inc.
The vulnerability is caused due to a boundary error in "ext.dll" when processing HTTP requests. This can be exploited to cause a buffer overflow by supplying a specially crafted HTTP request with an overly long "mfcisapicommand" parameter (more than 250 bytes).

affected-products-logoAffected Products

Working Resources Inc. BadBlue 2.55.

Impact logoImpact

System compromise, arbitrary code execution.

recomended-action-logoRecommended Actions

Upgrade to Working Resources Inc. BadBlue 2.61 or newer.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)