Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-0042
Description:Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-0042
Cert/CC Advisory: TA07-191A
http://www.us-cert.gov/cas/techalerts/TA07-191A.html
HPdes Security Advisory: SSRT071446
http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html
http://security-assessment.com/files/advisories/2007-07-11_Multiple_.NET_Null_Byte_Injection_Vulnerabilities.pdf
Microsoft Security Bulletin: MS07-040
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2070
http://www.securitytracker.com/id?1018356
http://secunia.com/advisories/26003
http://www.vupen.com/english/advisories/2007/2482




© 1998-2025 E-Soft Inc. All rights reserved.