CVE-2015-1648

Microsoft .NET Framework <4.6 - Info Disclosure

Title source: llm
STIX 2.1

Description

ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sensitive configuration-file information via a crafted request, aka "ASP.NET Information Disclosure Vulnerability."

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032116

Scores

EPSS 0.3465
EPSS Percentile 98.3%

Details

CWE
CWE-19
Status published
Products (8)
microsoft/.net_framework 1.1 sp1
microsoft/.net_framework 2.0 sp2
microsoft/.net_framework 3.5
microsoft/.net_framework 3.5.1
microsoft/.net_framework 4.0
microsoft/.net_framework 4.5
microsoft/.net_framework 4.5.1
microsoft/.net_framework 4.5.2
Published Apr 14, 2015
Tracked Since Feb 18, 2026