Vulnerability CVE-2006-6104


Published: 2006-12-21   Modified: 2012-02-12

Description:
The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Mono XSP ASP.NET Server sourcecode disclosure vulnerability
Jos Ramn Palanco
29.12.2006

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
MONO -> XSP 

 References:
http://fedoranews.org/cms/node/2400
http://fedoranews.org/cms/node/2401
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0002.html
http://security.gentoo.org/glsa/glsa-200701-12.xml
http://securityreason.com/securityalert/2082
http://securitytracker.com/id?1017430
http://www.eazel.es/advisory007-mono-xsp-source-disclosure-vulnerability.html
http://www.mandriva.com/security/advisories?name=MDKSA-2006:234
http://www.securityfocus.com/archive/1/454962/100/0/threaded
http://www.securityfocus.com/bid/21687
http://www.ubuntu.com/usn/usn-397-1
http://www.vupen.com/english/advisories/2006/5099
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2092

Copyright 2021, cxsecurity.com

 

Back to Top