CVE-2006-6104
Summary
| CVE | CVE-2006-6104 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-21 19:28:00 UTC |
| Updated | 2018-10-17 21:46:00 UTC |
| Description | The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Mono XSP Source Code Information Disclosure Vulnerability | BID | www.securityfocus.com | Exploit, Patch |
| Fedora Core 6 update for mono - Advisories - Secunia | SECUNIA | secunia.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | Patch, Vendor Advisory |
| Ubuntu update for mono - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Fedora Core 5 update for mono - Secunia.com | SECUNIA | secunia.com | |
| Mono System.Web Source Code Disclosure Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Exploit, Patch, Vendor Advisory |
| usn/usn-397-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | Patch |
| Gentoo Linux Documentation -- Mono: Information disclosure | GENTOO | security.gentoo.org | |
| Gentoo update for mono - Advisories - Secunia | SECUNIA | secunia.com | |
| [SECURITY] Fedora Core 6 Update: mono-1.1.17.1-4.fc6 | FedoraNEWS.ORG | FEDORA | fedoranews.org | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Mandriva update for mono - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| SuSE Security announcements: [suse-security-announce] SUSE Security Announcement: mono-web ASP.net sourcecode disclosure (SUSE-SA:2007:002) | SUSE | lists.suse.com | |
| Eazel - Mono XSP ASP.NET Server sourcecode disclosure vulnerability | MISC | www.eazel.es | Exploit |
| Mono XSP ASP.NET Server sourcecode disclosure vulnerability - CXSecurity.com | SREASON | securityreason.com | |
| Mono Discloses File Source Code to Remote Users - SecurityTracker | SECTRACK | securitytracker.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SUSE update for mono - Advisories - Secunia | SECUNIA | secunia.com | |
| 404 Not Found | FEDORA | fedoranews.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.