CVE-2008-2003

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
28/04/2008
Last modified:
09/04/2025

Description

BadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which allows remote attackers to (1) cause a denial of service via multiple invocations of uninst.exe, and have an unknown impact via (2) badblue.exe and (3) dyndns.exe. NOTE: this can be leveraged for arbitrary remote code execution in conjunction with CVE-2007-6378.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:badblue:badblue:2.72:*:personal:*:*:*:*:*