VulnerabilityModified
CVE-2007-5473
StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a trailing (1) space or (2) dot, which is not properly handled by XSP.
MEDIUM 5.0EPSS 1.25%
Does this matter?
Lower severity and a low EPSS score (1.25%). Track it; it rarely justifies an emergency change on its own.
Description
StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a trailing (1) space or (2) dot, which is not properly handled by XSP.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.25% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mono/mono
- Source
- cve@mitre.org
References
- http://anonsvn.mono-project.com/viewcvs/trunk/mcs/class/System.Web/System.Web/StaticFileHandler.cs
- http://osvdb.org/41871
- http://secunia.com/advisories/27349
- http://www.securityfocus.com/bid/26166
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37341
- http://anonsvn.mono-project.com/viewcvs/trunk/mcs/class/System.Web/System.Web/StaticFileHandler.cs
- http://osvdb.org/41871
- http://secunia.com/advisories/27349
- http://www.securityfocus.com/bid/26166
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37341
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.