PT-2007-1535 · Microsoft · .Net Framework+1
Published
2007-07-10
·
Updated
2018-10-30
·
CVE-2007-0042
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft .NET Framework versions 1.0 through 2.0
Description
The issue is related to an interpretation conflict in ASP.NET within Microsoft .NET Framework, allowing remote attackers to access configuration files, obtain sensitive information, and possibly bypass security mechanisms. This is due to the different handling of %00 characters as a string terminator in POSIX functions and as a data character in .NET strings. An attacker could exploit this to download the contents of any Web page on an ASP.NET Web site, effectively bypassing its security features.
Recommendations
For Microsoft .NET Framework versions 1.0 through 2.0, update to a version that includes the fix for this issue to prevent information disclosure and potential security mechanism bypass.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
.Net Framework
Asp.Net