7.8
CVSSv2

CVE-2007-0042

Published: 10/07/2007 Updated: 30/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote malicious users to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft .net_framework 1.1

microsoft .net_framework 2.0

microsoft .net_framework 1.0

Exploits

source: wwwsecurityfocuscom/bid/24791/info Microsoft NET Framework is prone to multiple NULL-byte injection vulnerabilities because it fails to adequately sanitize user-supplied data An attacker can exploit these issues to access sensitive information that may aid in further attacks; other attacks are also possible wwwexampl ...