Vulnerabilities > CVE-2006-1300 - Information Disclosure vulnerability in Microsoft .Net Framework 2.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-033.NASL |
description | The remote host is running a version of the ASP.NET framework that contains a flaw that could allow an attacker to bypass the security of an ASP.NET website by accessing protected objects by their explicit names. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22027 |
published | 2006-07-11 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22027 |
title | MS06-033: Vulnerabilities in ASP.NET could allow information disclosure (917283) |
code |
|
Oval
accepted | 2007-02-20T13:40:31.216-05:00 | ||||||||
class | vulnerability | ||||||||
contributors |
| ||||||||
definition_extensions |
| ||||||||
description | Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name." | ||||||||
family | windows | ||||||||
id | oval:org.mitre.oval:def:419 | ||||||||
status | accepted | ||||||||
submitted | 2006-07-25T12:05:33 | ||||||||
title | .NET 2.0 Application Folder Information Disclosure Vulnerability | ||||||||
version | 27 |
References
- http://secunia.com/advisories/20999
- http://securitytracker.com/id?1016465
- http://www.osvdb.org/27153
- http://www.securityfocus.com/bid/18920
- http://www.vupen.com/english/advisories/2006/2751
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-033
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26802
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A419