about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Microsoft ASP.NET URI Canonicalization Unauthorized Web Access Vulnerability


Title Microsoft ASP.NET URI Canonicalization Unauthorized Web Access Vulnerability
Published 2004-10-06-12:00AM
Updated 2005-06-14-08:38PM
Class Input Validation Error
CVE   CAN-2004-0847
Remote  Yes
Local  No
Credit  The vendor reported this vulnerability.
Vulnerable  Microsoft .NET Framework 1.1 SP1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.0 SP3
Microsoft .NET Framework 1.0 SP2
Microsoft .NET Framework 1.0 SP1
Microsoft .NET Framework 1.0
Not Vulnerable  
Code   No exploit is required to leverage this issue. The following proof of concept has been provided:

Mozilla Web Browser based proof of concept:
http://www.example.com/secureDirectorysomefile.aspx

Microsoft Internet Explorer based proof of concept:
http://www.example.com/secureDirectory%5Csomefile.aspx
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 05:18:40 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
MAX_UNAUTH 200 /compo qhmy.blogb free sex m harpseal.c BOLLYWOODS WCWW.HOTSE sqlCmd down news for c 200 /compo qhmy.blogb sexi vidio qhmy.blogb qhmy.blogb Indian sch gdyjcmq.cn news for C qhmy.blogb qhmy.blogb php-/ cum on fac gallery 2 i...Freadm qhmy.blogb qhmy.blogb qhmy.blogb net cafa Www.Pakist allinurl: szsl.09mf. folladas 200 /compo qhmy.blogb boys 200 /compo news for c qhmy.blogb www.i8pk.c McAfee SSH Server www.asiasp 200 /compo world sex Www.india Www.Pakist www.qq1w.c pinkworld. mambo Remo Www.sex_oc