PT-2011-3518 · Microsoft · .Net Framework 4+2

CVE-2011-1977

·

Publicado

2011-08-10

·

Atualizado

2023-12-07

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework 4 Chart Control for Microsoft .NET Framework 3.5 SP1
Description An information disclosure issue exists due to the improper handling of special characters within a specially crafted URI by Microsoft Chart controls. This allows remote attackers to read arbitrary files, including sensitive information stored in files like web.config, within the web site directory or subdirectories. The consequences depend on the nature of the disclosed information. This issue does not allow code execution or direct user rights elevation but could facilitate further system compromise.
Recommendations For Microsoft .NET Framework 4, update to a version that properly verifies functions in URIs. For Chart Control for Microsoft .NET Framework 3.5 SP1, apply the necessary patch to correct the handling of special characters in URIs. As a temporary workaround, consider restricting access to sensitive files within the web site directory or subdirectories to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1977

Produtos afetados

.Net Framework
Chart Control For Microsoft .Net Framework 3.5 Sp1
.Net Framework 4