CVE-2011-1977
published 2011-08-10CVE-2011-1977: The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs…
PriorityP434medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
21.37%
97.3th percentile
The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka "Chart Control Information Disclosure Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | chart_control_for_microsoft_net_framework | — | — |
| microsoft | net_framework | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
http://www.us-cert.gov/cas/techalerts/TA11-221A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-066https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12970http://www.us-cert.gov/cas/techalerts/TA11-221A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-066https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12970
2011-08-10
Published