StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a trailing (1) space or (2) dot, which is not properly handled by XSP.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/26166 | vdb entry |
http://osvdb.org/41871 | vdb entry |
http://secunia.com/advisories/27349 | third party advisory |
http://anonsvn.mono-project.com/viewcvs/trunk/mcs/class/System.Web/System.Web/StaticFileHandler.cs | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37341 | vdb entry |