Vulnerability Name: | CVE-2011-1977 (CCN-68832) | ||||||||
Assigned: | 2011-08-09 | ||||||||
Published: | 2011-08-09 | ||||||||
Updated: | 2020-09-28 | ||||||||
Summary: | The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka "Chart Control Information Disclosure Vulnerability." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-1977 Source: CCN Type: SA45508 Microsoft .NET Framework Chart Control Information Disclosure Source: CCN Type: Microsoft Security Bulletin MS11-066 Vulnerability in Microsoft Chart Control Could Allow Information Disclosure (2567943) Source: CCN Type: BID-48985 Microsoft .NET Framework Chart Control Information Disclosure Vulnerability Source: CERT Type: US Government Resource TA11-221A Source: MS Type: UNKNOWN MS11-066 Source: XF Type: UNKNOWN ms-chart-control-info-disclosure(68832) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:12970 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |