// For flags

CVE-2006-6104

Mono XSP 1.x/2.0 - Source Code Information Disclosure

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.

La clase System.Web del XSP para el servidor ASP.NET desde la versión 1.1 hasta la 2.0 en Mono no verifica apropiadamente los nombres de rutas locales, lo cual permite a atacantes remotos (1)leer el código fuente añadiendo un espacio (%20) a la URI y (2) leer las credenciales mediante una petición al Web.Config%20.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-11-24 CVE Reserved
  • 2006-12-20 First Exploit
  • 2006-12-21 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-26 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mono
Search vendor "Mono"
Xsp
Search vendor "Mono" for product "Xsp"
1.1
Search vendor "Mono" for product "Xsp" and version "1.1"
-
Affected
Mono
Search vendor "Mono"
Xsp
Search vendor "Mono" for product "Xsp"
1.2.1
Search vendor "Mono" for product "Xsp" and version "1.2.1"
-
Affected
Mono
Search vendor "Mono"
Xsp
Search vendor "Mono" for product "Xsp"
2.0
Search vendor "Mono" for product "Xsp" and version "2.0"
-
Affected