Vulnerability Name: | CCN-71808 | ||||||
Published: | 2011-12-13 | ||||||
Updated: | 2011-12-13 | ||||||
Summary: | Microsoft .NET Framework could allow a remote attacker to bypass security restrictions, caused by an error in the SaveAs() function. An attacker could exploit this vulnerability to bypass restrictions regarding file upload types to upload arbitrary ASP files on the system. | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||
Vulnerability Consequences: | Bypass Security | ||||||
References: | Source: CCN Type: Microsoft Web site .NET Framework Source: XF Type: UNKNOWN ms-dotnet-saveas-security-bypass(71808) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |