|
|
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3416
The information has been provided by Kestutis Gudinavicius.
|
| |
Vulnerable Systems:
* Microsoft .NET Framework 4.0
*Microsoft .NET Framework 3.5 SP1
*Microsoft .NET Framework 3.5
*Microsoft .NET Framework 2.0 SP2
*Microsoft .NET Framework 2.0 SP1
*Microsoft .NET Framework 2.0
*Microsoft .NET Framework 1.1 SP3
*Microsoft .NET Framework 1.1 SP2
*Microsoft .NET Framework 1.1 SP1
*Microsoft .NET Framework 1.1
Microsoft .NET Framework is prone to a authentication-bypass vulnerability in ASP.NET.
An attacker can exploit this issue to gain unauthorized access to another users account. Successful exploits will allow attackers to execute arbitrary commands with the privileges of the targeted user.
Vendor Status:
Microsoft has issued an update to correct this vulnerability
Patch Availability:
http://technet.microsoft.com/en-us/security/bulletin/ms11-100
CVE Information:
CVE-2011-3416
|
|
|