Microsoft_ASP_NET_Canonicalization_Vulnerability_attack

Strike ID:
G04-3nj01
CVSS:
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2004

Description

A vulnerability exists in the ASP.NET programming framework within the authentication schema. The error exists in the canonicalization of requested ASP.NET resource paths. This flaw can be exploited by remote unauthenticated users to access server secured resources without prior authorization. The vulnerable target machine will execute a restricted ASP.NET script and serve the resulting web page to the attacker. The attacker will not be prompted to verify his credentials before being served the restricted content.

CVE