CVE-2004-0847
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 75.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 75.70% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- microsoft/asp.net
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/ntbugtraq/2004-q3/0221.htmlExploit, Vendor Advisory
- http://sourceforge.net/mailarchive/forum.php?thread_id=5671607&forum_id=24754Broken Link
- http://www.kb.cert.org/vuls/id/283646Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/11342Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA05-039A.htmlThird Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-004
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17644Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3556Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4987Third Party Advisory
- http://archives.neohapsis.com/archives/ntbugtraq/2004-q3/0221.htmlExploit, Vendor Advisory
- http://sourceforge.net/mailarchive/forum.php?thread_id=5671607&forum_id=24754Broken Link
- http://www.kb.cert.org/vuls/id/283646Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/11342Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA05-039A.htmlThird Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-004
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17644Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3556Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4987Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.