CVE-2006-6104 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 5.2% (pctl 92)
Patch early
A public exploit exists.
Description
The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 5.25% — more likely to be exploited than 92% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-12-21 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| mono | xsp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mono XSP 1.x/2.0 - Source Code Information Disclosure | 2006-12-20 |
References
- http://fedoranews.org/cms/node/2400
- http://fedoranews.org/cms/node/2401
- http://lists.suse.com/archive/suse-security-announce/2007-Jan/0002.html
- http://secunia.com/advisories/23432
- http://secunia.com/advisories/23435
- http://secunia.com/advisories/23462
- http://secunia.com/advisories/23597
- http://secunia.com/advisories/23727
- http://secunia.com/advisories/23776
- http://secunia.com/advisories/23779
- http://security.gentoo.org/glsa/glsa-200701-12.xml
- http://securityreason.com/securityalert/2082
- http://securitytracker.com/id?1017430
- http://www.eazel.es/advisory007-mono-xsp-source-disclosure-vulnerability.html
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:234
- http://www.securityfocus.com/archive/1/454962/100/0/threaded
- http://www.securityfocus.com/bid/21687
- http://www.ubuntu.com/usn/usn-397-1
- http://www.vupen.com/english/advisories/2006/5099
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2092
→ the Explorer · watch your stack · NVD