CVE-2006-1364

HIGH

ASP.NET < 1.1 - Denial of Service via COM Component Requests

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1364. PoCs published by Debasis Mohanty.

AI-analyzed exploit summary This exploit targets a denial-of-service (DoS) vulnerability in ASP.NET applications by sending multiple HTTP requests to restricted resources. It repeatedly requests sensitive files and COM component references to exhaust server resources.

Description

Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Debasis Mohanty · cdoswindows
https://www.exploit-db.com/exploits/1601

This exploit targets a denial-of-service (DoS) vulnerability in ASP.NET applications by sending multiple HTTP requests to restricted resources. It repeatedly requests sensitive files and COM component references to exhaust server resources.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft ASP.NET (versions affected by CVE-2006-1364)
No auth needed
Prerequisites: Network access to the target web server · Target running vulnerable ASP.NET application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/428622/100/0/threaded
Broken Link, Third Party Advisory x_refsource_misc
http://hackingspirits.com/vuln-rnd/w3wp-remote-dos.zip
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015825
Exploit, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17188
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25392
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1601
Exploit, Third Party Advisory x_refsource_misc
http://www.securiteam.com/windowsntfocus/5KP0O0KI0Y.html
Third Party Advisory mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044291.html
Third Party Advisory mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044292.html

Scores

CVSS v3 7.5
EPSS 0.5874
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (2)
microsoft/asp.net 1.1 sp1
microsoft/asp.net < 1.1
Published Mar 23, 2006
Tracked Since Feb 18, 2026