Microsoft ASP.NET Application Folder Information Disclosure Vulnerability
BID:18920
Info
Microsoft ASP.NET Application Folder Information Disclosure Vulnerability
| Bugtraq ID: | 18920 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-1300 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2006 12:00AM |
| Updated: | Jul 13 2006 06:48PM |
| Credit: | Urs Eichmann is credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft .NET Framework 2.0 |
| Not Vulnerable: | |
Discussion
Microsoft ASP.NET Application Folder Information Disclosure Vulnerability
ASP.NET is prone to an information-disclosure vulnerability. This issue is due to a failure in the applications to properly validate user-supplied input.
An attacker can exploit this issue to retrieve potentially sensitive information. Information retrieved may aid in further attacks.
ASP.NET is prone to an information-disclosure vulnerability. This issue is due to a failure in the applications to properly validate user-supplied input.
An attacker can exploit this issue to retrieve potentially sensitive information. Information retrieved may aid in further attacks.
Exploit / POC
Microsoft ASP.NET Application Folder Information Disclosure Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Microsoft ASP.NET Application Folder Information Disclosure Vulnerability
Solution:
The vendor has released an advisory to address this issue in supported versions of the affected software.
Microsoft .NET Framework 2.0
Solution:
The vendor has released an advisory to address this issue in supported versions of the affected software.
Microsoft .NET Framework 2.0
-
Microsoft NDP 2.0 ASP.Net Security Update
http://www.microsoft.com/downloads/details.aspx?familyid=56A1777B-9758 -489F-8BE8-5177AAF488D1&displaylang=en
References
Microsoft ASP.NET Application Folder Information Disclosure Vulnerability
References:
References:
- .Net Home (Microsoft)
- Microsoft Security Bulletin MS06-033 (Microsoft)
- Microsoft Technet Security (Microsoft)