Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-6104
Description:The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.
Test IDs: 1.3.6.1.4.1.25623.1.0.57724   1.3.6.1.4.1.25623.1.0.59082   1.3.6.1.4.1.25623.1.0.59447   1.3.6.1.4.1.25623.1.0.58036   1.3.6.1.4.1.25623.1.0.59448   1.3.6.1.4.1.25623.1.0.57972  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-6104
BugTraq ID: 21687
http://www.securityfocus.com/bid/21687
Bugtraq: 20061220 Mono XSP ASP.NET Server sourcecode disclosure vulnerability (Google Search)
http://www.securityfocus.com/archive/1/454962/100/0/threaded
http://fedoranews.org/cms/node/2400
http://fedoranews.org/cms/node/2401
http://security.gentoo.org/glsa/glsa-200701-12.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:234
http://www.eazel.es/advisory007-mono-xsp-source-disclosure-vulnerability.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2092
http://securitytracker.com/id?1017430
http://secunia.com/advisories/23432
http://secunia.com/advisories/23435
http://secunia.com/advisories/23462
http://secunia.com/advisories/23597
http://secunia.com/advisories/23727
http://secunia.com/advisories/23776
http://secunia.com/advisories/23779
http://securityreason.com/securityalert/2082
SuSE Security Announcement: SUSE-SA:2007:002 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0002.html
http://www.ubuntu.com/usn/usn-397-1
http://www.vupen.com/english/advisories/2006/5099




© 1998-2024 E-Soft Inc. All rights reserved.