G06-40401
CVSS:
5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
False Positive:
f
Variants:
1
Year:
2006
Description
An information disclosure vulnerability has been identified in Microsoft ASP.NET. The flaw is caused by an improper checking of the user supplied URLs. An attacker may exploit this vulnerability to access any object in the ASP.NET Application folder. In the case of an unsuccessful attack, the IIS server responds with HTTP 404 - File not found message. In cases where the attack is successful, the server responds with the content of the file under Application Code folder, app_code, located inside the web root directory.
CVE
References
http://securitytracker.com/id?1016465