PT-2007-1535 · Microsoft · .Net Framework+1

Published

2007-07-10

·

Updated

2018-10-30

·

CVE-2007-0042

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework versions 1.0 through 2.0
Description The issue is related to an interpretation conflict in ASP.NET within Microsoft .NET Framework, allowing remote attackers to access configuration files, obtain sensitive information, and possibly bypass security mechanisms. This is due to the different handling of %00 characters as a string terminator in POSIX functions and as a data character in .NET strings. An attacker could exploit this to download the contents of any Web page on an ASP.NET Web site, effectively bypassing its security features.
Recommendations For Microsoft .NET Framework versions 1.0 through 2.0, update to a version that includes the fix for this issue to prevent information disclosure and potential security mechanism bypass.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0042

Affected Products

.Net Framework
Asp.Net