peter bassill · operator
$ cve CVE-2006-6104 JSON

CVE-2006-6104 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 5.2% (pctl 92)

Patch early

A public exploit exists.

Description

The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS5.25% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2006-12-21
Last modified2026-06-16

Affected (1)

VendorProduct
monoxsp

Public exploits

SourceTitleDate
exploit-dbMono XSP 1.x/2.0 - Source Code Information Disclosure2006-12-20

References

→ the Explorer  ·  watch your stack  ·  NVD