exploit-db-mirror/exploits/asp/webapps/24666.txt
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

11 lines
No EOL
552 B
Text

source: https://www.securityfocus.com/bid/11342/info
Microsoft ASP.NET is reported prone to a remote information-disclosure vulnerability because the application fails to properly secure documents when handling malformed URI requests.
An attacker may leverage this issue to bypass authentication required to access files in secured directories.
Mozilla Web Browser based proof of concept:
http://www.example.com/secureDirectory\somefile.aspx
Microsoft Internet Explorer based proof of concept:
http://www.example.com/secureDirectory%5Csomefile.aspx