9.8
CVSSv3

CVE-2004-0847

Published: 03/11/2004 Updated: 12/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Microsoft .NET forms authentication capability for ASP.NET allows remote malicious users to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft asp.net 1.1

microsoft asp.net

Exploits

source: wwwsecurityfocuscom/bid/11342/info Microsoft ASPNET is reported prone to a remote information-disclosure vulnerability because the application fails to properly secure documents when handling malformed URI requests An attacker may leverage this issue to bypass authentication required to access files in secured directories Mo ...