Mono Discloses File Source Code to Remote Users
|
|
SecurityTracker Alert ID: 1017430
|
|
SecurityTracker URL: http://securitytracker.com/id?1017430
|
|
CVE Reference: CVE-2006-6104
(Links to External Site)
|
Date: Dec 21 2006
|
Impact: Disclosure of user information
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Description: A vulnerability was reported in Mono. A remote user can view source code on the target system.
A remote user can supply a specially crafted request appended with a space character (%20) to view the source of files on the target
system.
A demonstration exploit URL is provided:
http://[target]/app/Default.aspx%20
A remote user can also obtain the
'Web.Config' file.
The vendor was notified on November 30, 2006.
Jose Ramon Palanco discovered this vulnerability.
The
original advisory is available at:
http://eazel.es/advisory007-mono-xsp-source-disclosure-vulnerability.html
|
Impact: A remote user can view source code on the target system.
|
Solution: The vendor has issued a fix, available via subversion.
|
Vendor URL: www.mono-project.com/ (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 21 Dec 2006 09:59:53 -0500
Subject: XSP (Mono ASP.NET server)
|
source disclosure attack
CVE-2006-6104
|
|