CVE-2004-0847

CRITICAL EXPLOITED

ASP.NET - Path Traversal via Backslash Character

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2004-0847 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including anonymous.

AI-analyzed exploit summary This exploit leverages a URI parsing vulnerability in Microsoft ASP.NET to bypass authentication and access files in secured directories by using malformed backslash characters in the URL path.

Description

The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · textwebappsasp
https://www.exploit-db.com/exploits/24666

This exploit leverages a URI parsing vulnerability in Microsoft ASP.NET to bypass authentication and access files in secured directories by using malformed backslash characters in the URL path.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Microsoft ASP.NET (versions affected in 2004)
No auth needed
Prerequisites: Access to the target web server · Knowledge of secured directory and file paths
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA05-039A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17644
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/283646
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11342
Exploit, Vendor Advisory mailing-list x_refsource_ntbugtraq
http://archives.neohapsis.com/archives/ntbugtraq/2004-q3/0221.html

Scores

CVSS v3 9.8
EPSS 0.4557
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2005-02-08
CWE
CWE-22
Status published
Products (2)
microsoft/asp.net 1.1 sp1
microsoft/asp.net < 1.1
Published Nov 03, 2004
Tracked Since Feb 18, 2026