Microsoft_ASP_NET_Application_Folder_Information_Disclosure_attack

Strike ID:
G06-40401
CVSS:
5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
False Positive:
f
Variants:
1
Year:
2006

Description

An information disclosure vulnerability has been identified in Microsoft ASP.NET. The flaw is caused by an improper checking of the user supplied URLs. An attacker may exploit this vulnerability to access any object in the ASP.NET Application folder. In the case of an unsuccessful attack, the IIS server responds with HTTP 404 - File not found message. In cases where the attack is successful, the server responds with the content of the file under Application Code folder, app_code, located inside the web root directory.

CVE

References

Bid