Microsoft .Net Framework 2.0 - Multiple Null Byte Injection Vulnerabilities

EDB-ID:

30281




Platform:

Windows

Date:

2007-07-06


source: https://www.securityfocus.com/bid/24791/info

Microsoft .NET Framework is prone to multiple NULL-byte injection vulnerabilities because it fails to adequately sanitize user-supplied data.

An attacker can exploit these issues to access sensitive information that may aid in further attacks; other attacks are also possible. 

http://www.example.com/[path]/somescript.asp%00