Microsoft .NET Framework v1.1 Security BypassID: oval:org.mitre.oval:def:3556 | Date: (C)2005-03-31 (M)2023-05-15 |
Class: VULNERABILITY | Family: windows |
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "\\\%5C" (encoded backslash), aka "Path Validation Vulnerability."
Platform: |
Microsoft Windows 2000 |
Microsoft Windows XP |
Microsoft Windows Server 2003 |
Product: |
Microsoft .NET Framework 1.0 |
Microsoft .NET Framework 1.1 |