CVE Tools

Working-resources-inc

14 CVEs tracked since 2001. Since Apr 2001, none of them reached CISA KEV.

Working-resources-inc CVEs per month

Apr 2001 to Jun 2005. Point at a month, or focus the strip and use the arrow keys.
Working-resources-inc CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2001-0410
2001-05null or fewer
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-09null or fewer
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-0320
2002-04null or fewer
2002-0520
2002-06null or fewer
2002-0710
2002-0830
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-0510
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-0640

Products

The products that kept showing up in Working-resources-inc's monthly top three, with their CVEs summed over those months.

  1. Badblue147 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Working-resources-inc.

  1. CVE-2002-2289soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.5.0
  2. CVE-2002-2170Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, wh...7.5
  3. CVE-2004-2374BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML.5.0
  4. CVE-2002-1973Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in ...7.5
  5. CVE-2002-1684Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (...5.0
  6. CVE-2002-1683Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.4.3
  7. CVE-2002-1685Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into...4.3
  8. CVE-2005-0595Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.7.5
  9. CVE-2004-1727BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.5.0
  10. CVE-2002-1541BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).7.5
  11. CVE-2003-0332The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attacker...7.6
  12. CVE-2002-1021BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.5.0
  13. CVE-2002-1023BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.5.0
  14. CVE-2002-1022BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges.7.5
  15. CVE-2002-0800BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end.5.0

The record

Peak rank
#23 in Aug 2002
Busiest month shown
Jun 2005, 4 CVEs
Months with a KEV entry
0 since Apr 2001
Monthly snapshots
7 since 2001
Working-resources-inc's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store