PT-2011-3518 · Microsoft · .Net Framework 4+2
CVE-2011-1977
·
Publicado
2011-08-10
·
Atualizado
2023-12-07
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework 4
Chart Control for Microsoft .NET Framework 3.5 SP1
Description
An information disclosure issue exists due to the improper handling of special characters within a specially crafted URI by Microsoft Chart controls. This allows remote attackers to read arbitrary files, including sensitive information stored in files like web.config, within the web site directory or subdirectories. The consequences depend on the nature of the disclosed information. This issue does not allow code execution or direct user rights elevation but could facilitate further system compromise.
Recommendations
For Microsoft .NET Framework 4, update to a version that properly verifies functions in URIs.
For Chart Control for Microsoft .NET Framework 3.5 SP1, apply the necessary patch to correct the handling of special characters in URIs.
As a temporary workaround, consider restricting access to sensitive files within the web site directory or subdirectories to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
.Net Framework
Chart Control For Microsoft .Net Framework 3.5 Sp1
.Net Framework 4