Summary
A canonicalization vulnerability exists in ASP.NET that could allow an attacker to bypass the security of an ASP.NET Web site
and gain unauthorized access. An attacker who successfully exploited this vulnerability could take a variety of actions,
depending on the specific contents of the website.
Solution
Microsoft has released a patch to correct this issue, you can download it from the following web site:
http://www.microsoft.com/technet/security/Bulletin/MS05-004.mspx
Severity
Classification
-
CVE CVE-2004-0847 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Microsoft Forefront Protection For Exchange RCE Vulnerability (2927022)
- Microsoft Active Directory LDAP Remote Code Execution Vulnerability (969805)
- Microsoft Internet Explorer Multiple Code Execution Vulnerabilities (974455)
- Microsoft Foundation Class (MFC) Library Remote Code Execution Vulnerability (2500212)
- Microsoft DirectShow Remote Code Execution Vulnerability (961373)