Summary
A canonicalization vulnerability exists in ASP.NET that could allow an attacker to bypass the security of an ASP.NET Web site
and gain unauthorized access. An attacker who successfully exploited this vulnerability could take a variety of actions,
depending on the specific contents of the website.
Solution
Microsoft has released a patch to correct this issue, you can download it from the following web site:
http://www.microsoft.com/technet/security/Bulletin/MS05-004.mspx
Severity
Classification
-
CVE CVE-2004-0847 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Microsoft Bluetooth Stack Remote Code Execution Vulnerability (2566220)
- Microsoft .NET Framework Open Data Protocol DOS Vulnerability (2769327)
- Microsoft Excel Remote Code Execution Vulnerabilities (968557)
- Active Directory Could Allow Remote Code Execution Vulnerability (957280)
- Microsoft DNS Resolution Remote Code Execution Vulnerability (2509553)