Microsoft .Net Framework 2.0 - Multiple Null Byte Injection Vulnerabilities



EKU-ID: 35368 CVE: CVE-2007-0042;OSVDB-35955 OSVDB-ID:
Author: Paul Craig Published: 2007-07-06 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/24791/info

Microsoft .NET Framework is prone to multiple NULL-byte injection vulnerabilities because it fails to adequately sanitize user-supplied data.

An attacker can exploit these issues to access sensitive information that may aid in further attacks; other attacks are also possible.

http://www.example.com/[path]/somescript.asp%00