Security Advisory

CVE-2006-6104

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2006-12-21 19:00:00
Last updated 2024-08-07 20:12:31
Assigner redhat
State PUBLISHED

Description

The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.