Working-resources-inc
14 CVEs tracked since 2001. Since Apr 2001, none of them reached CISA KEV.
Working-resources-inc CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2001-04 | 1 | 0 |
| 2001-05 | null or fewer | |
| 2001-06 | null or fewer | |
| 2001-07 | null or fewer | |
| 2001-08 | null or fewer | |
| 2001-09 | null or fewer | |
| 2001-10 | null or fewer | |
| 2001-11 | null or fewer | |
| 2001-12 | null or fewer | |
| 2002-01 | null or fewer | |
| 2002-02 | null or fewer | |
| 2002-03 | 2 | 0 |
| 2002-04 | null or fewer | |
| 2002-05 | 2 | 0 |
| 2002-06 | null or fewer | |
| 2002-07 | 1 | 0 |
| 2002-08 | 3 | 0 |
| 2002-09 | null or fewer | |
| 2002-10 | null or fewer | |
| 2002-11 | null or fewer | |
| 2002-12 | null or fewer | |
| 2003-01 | null or fewer | |
| 2003-02 | null or fewer | |
| 2003-03 | null or fewer | |
| 2003-04 | null or fewer | |
| 2003-05 | 1 | 0 |
| 2003-06 | null or fewer | |
| 2003-07 | null or fewer | |
| 2003-08 | null or fewer | |
| 2003-09 | null or fewer | |
| 2003-10 | null or fewer | |
| 2003-11 | null or fewer | |
| 2003-12 | null or fewer | |
| 2004-01 | null or fewer | |
| 2004-02 | null or fewer | |
| 2004-03 | null or fewer | |
| 2004-04 | null or fewer | |
| 2004-05 | null or fewer | |
| 2004-06 | null or fewer | |
| 2004-07 | null or fewer | |
| 2004-08 | null or fewer | |
| 2004-09 | null or fewer | |
| 2004-10 | null or fewer | |
| 2004-11 | null or fewer | |
| 2004-12 | null or fewer | |
| 2005-01 | null or fewer | |
| 2005-02 | null or fewer | |
| 2005-03 | null or fewer | |
| 2005-04 | null or fewer | |
| 2005-05 | null or fewer | |
| 2005-06 | 4 | 0 |
Products
The products that kept showing up in Working-resources-inc's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Working-resources-inc.
- CVE-2002-2289soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.5.0
- CVE-2002-2170Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, wh...7.5
- CVE-2004-2374BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML.5.0
- CVE-2002-1973Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in ...7.5
- CVE-2002-1684Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (...5.0
- CVE-2002-1683Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.4.3
- CVE-2002-1685Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into...4.3
- CVE-2005-0595Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.7.5
- CVE-2004-1727BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.5.0
- CVE-2002-1541BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).7.5
- CVE-2003-0332The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attacker...7.6
- CVE-2002-1021BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.5.0
- CVE-2002-1023BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.5.0
- CVE-2002-1022BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges.7.5
- CVE-2002-0800BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end.5.0
The record
- Peak rank
- #23 in Aug 2002
- Busiest month shown
- Jun 2005, 4 CVEs
- Months with a KEV entry
- 0 since Apr 2001
- Monthly snapshots
- 7 since 2001