Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxfc-g96x-mm56

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."

The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."

EPSS

Процентиль: 98%
0.52826
Средний

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
больше 21 года назад

The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."

EPSS

Процентиль: 98%
0.52826
Средний

9.8 Critical

CVSS3

Дефекты

CWE-22