CVE-2004-0847
CRITICAL EXPLOITEDASP.NET - Path Traversal via Backslash Character
Title source: llmExploitation Summary
CVE-2004-0847 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including anonymous.
AI-analyzed exploit summary This exploit leverages a URI parsing vulnerability in Microsoft ASP.NET to bypass authentication and access files in secured directories by using malformed backslash characters in the URL path.
Description
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."
Exploits (1)
This exploit leverages a URI parsing vulnerability in Microsoft ASP.NET to bypass authentication and access files in secured directories by using malformed backslash characters in the URL path.
References (9)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H