CVE-2010-4225Sensitive Information Exposure in Mono

Severity
5.0MEDIUMNVD
EPSS
0.6%
top 31.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 11
Latest updateMay 17

Description

Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2.8.2 allows remote attackers to obtain the source code for .aspx (ASP.NET) applications via unknown vectors related to an "unloading bug."

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/mono< mono 2.6.7-5 (bookworm)
Debianmono/mono< 2.6.7-5+3
NVDmono/mono2.8, 2.8.1+1

🔴Vulnerability Details

3
GHSA
GHSA-25f3-2w4g-m595: Unspecified vulnerability in the mod_mono module for XSP in Mono 22022-05-17
OSV
CVE-2010-4225: Unspecified vulnerability in the mod_mono module for XSP in Mono 22011-01-11
CVEList
CVE-2010-4225: Unspecified vulnerability in the mod_mono module for XSP in Mono 22011-01-11

💥Exploits & PoCs

1
Exploit-DB
CA eTrust PestPatrol - ActiveX Control Buffer Overflow (Metasploit)2010-11-11

📋Vendor Advisories

1
Debian
CVE-2010-4225: mono - Unspecified vulnerability in the mod_mono module for XSP in Mono 2.8.x before 2....2010

💬Community

2
Bugzilla
CVE-2010-4225 mod_mono: remote source code exposure flaw [fedora-all]2011-01-12
Bugzilla
CVE-2010-4225 mod_mono: remote source code exposure flaw2011-01-12