Microsoft ASP.NET Malformed HTTP Request Information Disclosure Vulnerability
BID:10292
Info
Microsoft ASP.NET Malformed HTTP Request Information Disclosure Vulnerability
| Bugtraq ID: | 10292 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2004 12:00AM |
| Updated: | May 06 2004 12:00AM |
| Credit: | Discovery is credited to Aaron C. Newman <[email protected]>. |
| Vulnerable: |
Microsoft ASP.NET 1.1 Microsoft ASP.NET 1.0 Microsoft ASP.NET 0 Microsoft ASP 3.0 |
| Not Vulnerable: | |
Discussion
Microsoft ASP.NET Malformed HTTP Request Information Disclosure Vulnerability
It has been reported that ASP.NET may be prone to a remote information disclosure vulnerability that could allow an attacker to disclose sensitive information. This issue occurs when a malformed cookie header is sent to a server via a HTTP GET request.
Successful exploitation of this issue may allow a remote attacker to disclose sensitive information, which could be used to launch further attacks against a vulnerable system.
It has been reported that ASP.NET may be prone to a remote information disclosure vulnerability that could allow an attacker to disclose sensitive information. This issue occurs when a malformed cookie header is sent to a server via a HTTP GET request.
Successful exploitation of this issue may allow a remote attacker to disclose sensitive information, which could be used to launch further attacks against a vulnerable system.
Exploit / POC
Microsoft ASP.NET Malformed HTTP Request Information Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Microsoft ASP.NET Malformed HTTP Request Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft ASP.NET Malformed HTTP Request Information Disclosure Vulnerability
References:
References:
- Technet Security (Microsoft)
- [AppSecInc Security Alert] Microsoft Active Server Pages Cookie Retrieval Issue ("Aaron C. Newman \(Application Security, Inc.\)"
)