Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-1977 | First vendor Publication | 2011-08-10 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka "Chart Control Information Disclosure Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1977 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-200 | Information Exposure |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:12970 | |||
Oval ID: | oval:org.mitre.oval:def:12970 | ||
Title: | Chart Control Information Disclosure Vulnerability | ||
Description: | The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka "Chart Control Information Disclosure Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2011-1977 | Version: | 5 |
Platform(s): | Microsoft Windows XP Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 | Product(s): | Microsoft .NET Framework Chart Control for Microsoft .NET Framework 3.5 Service Pack 1 |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2011-08-11 | Name : Microsoft .NET Framework Chart Control Information Disclosure Vulnerability (... File : nvt/secpod_ms11-066.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
74403 | Microsoft .NET Framework Chart Control Special URI Character GET Request Pars... |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2011-08-11 | IAVM : 2011-B-0100 - Microsoft ASP.NET Chart Control Information Disclosure Vulnerability Severity : Category II - VMSKEY : V0029781 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Windows .NET Chart Control directory traversal attempt RuleID : 19694 - Revision : 7 - Type : SERVER-WEBAPP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-08-09 | Name : The remote Windows host has an ASP.NET control that could allow information d... File : smb_nt_ms11-066.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:04:28 |
|
2024-11-28 12:25:45 |
|
2024-08-02 12:16:35 |
|
2024-08-02 01:04:41 |
|
2024-02-02 01:16:06 |
|
2024-02-01 12:04:35 |
|
2023-12-07 21:28:02 |
|
2023-09-05 12:15:04 |
|
2023-09-05 01:04:27 |
|
2023-09-02 12:15:08 |
|
2023-09-02 01:04:32 |
|
2023-08-12 12:18:17 |
|
2023-08-12 01:04:32 |
|
2023-08-11 12:15:13 |
|
2023-08-11 01:04:40 |
|
2023-08-06 12:14:38 |
|
2023-08-06 01:04:33 |
|
2023-08-04 12:14:43 |
|
2023-08-04 01:04:34 |
|
2023-07-14 12:14:42 |
|
2023-07-14 01:04:31 |
|
2023-03-29 01:16:37 |
|
2023-03-28 12:04:37 |
|
2022-10-11 12:13:06 |
|
2022-10-11 01:04:17 |
|
2020-11-24 12:07:17 |
|
2020-09-28 17:22:43 |
|
2020-05-23 00:28:33 |
|
2019-05-09 12:03:53 |
|
2019-02-26 17:19:36 |
|
2018-10-31 00:20:14 |
|
2018-10-13 05:18:32 |
|
2018-09-20 12:08:59 |
|
2017-09-19 09:24:27 |
|
2016-09-30 01:03:01 |
|
2016-08-31 12:02:45 |
|
2016-08-05 12:03:06 |
|
2016-06-29 00:20:24 |
|
2016-04-26 20:46:15 |
|
2014-02-17 11:02:31 |
|
2014-01-19 21:27:50 |
|
2013-11-11 12:39:24 |
|
2013-05-10 23:00:55 |
|