What You Should Know About a Reported Vulnerability in Microsoft ASP.NET
Published: October 5, 2004 | Updated: October 7, 2004
Microsoft is continuing to investigate a reported vulnerability in Microsoft ASP.NET. Reports have indicated that an attacker could send specially crafted requests to a Web server running ASP.NET applications and bypass forms based authentication or Windows authorization configurations, and potentially view secured content without providing the proper credentials. Our initial investigation has revealed that all versions of ASP.NET could be affected, independent of the installed IIS version or IIS components.
Microsoft strongly advises, as a preventativ

微软正在调查一个报告中的ASP.NET安全漏洞,攻击者可能通过构造特殊请求绕过基于表单的身份验证或Windows授权,无须正确凭证查看受保护内容。建议所有ASP.NET用户立即采取预防措施,如安装HTTP模块或编程检查规范化问题。
最低0.47元/天 解锁文章
5683





