Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-1364

Опубликовано: 23 мар. 2006
Источник: nvd
CVSS3: 7.5
CVSS2: 7.8
EPSS Средний

Описание

Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:microsoft:asp.net:*:*:*:*:*:*:*:*
Версия до 1.1 (включая)
cpe:2.3:a:microsoft:asp.net:1.1:sp1:*:*:*:*:*:*

EPSS

Процентиль: 96%
0.29481
Средний

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
github
почти 4 года назад

Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.

EPSS

Процентиль: 96%
0.29481
Средний

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-400