BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded % character at the end.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Badblue |
Working_resources_inc. |
1.7.0 (including) |
1.7.0 (including) |
References