VDB
CVE-2006-6104
CVE-2006-6104
PUBLISHED
CVSS 5 MEDIUM
The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.
EPSS 15.02% · 94.7th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
15.02%
94.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mono | xsp | 1.1, 1.2.1, 2.0 |
| n/a | n/a | * |
Timeline
- Dec 21, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- May 1, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 25, 2023 EPSS Score
References
- GLSA-200701-12 vendor-advisory
- 23597 third-party-advisory
- ADV-2006-5099 vdb
- SUSE-SA:2007:002 vendor-advisory
- 2082 third-party-advisory
- oval:org.mitre.oval:def:2092 vdb
- 20061220 Mono XSP ASP.NET Server sourcecode disclosure vulnerability mailing-list
- 1017430 vdb
- FEDORA-2007-067 vendor-advisory
- 23462 third-party-advisory
- 23727 third-party-advisory
- 23779 third-party-advisory
- MDKSA-2006:234 vendor-advisory
- 23776 third-party-advisory
- 21687 vdb
- http://www.eazel.es/advisory007-mono-xsp-source-disclosure-vulnerability.html url
- 23435 third-party-advisory
- 23432 third-party-advisory
- FEDORA-2007-068 vendor-advisory
- USN-397-1 vendor-advisory
…and 1 more