CVE: CVE-2004-0847

Export to Word

The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."

Threat-Mapped Scoring

Score: 0.0

Priority: Unclassified

EPSS

Score: 0.64439
Percentile: 0.98342

CVSS Scoring

CVSS v3.0 Score: 9.8

Severity: CRITICAL

Mapped CWE(s)

All CAPEC(s)

CAPEC(s) with Mapped TTPs

Mapped ATT&CK TTPs

Affected Products

← Back to Home