CVE-2011-1977

Description

The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka Chart Control Information Disclosure Vulnerability.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
20.971

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft .NET Framework 4(KB2487367) x86 based systemsWindows
Security Update for Microsoft .NET Framework 4(KB2487367) x64 bases systemsWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-10826Security Update for Microsoft .NET Framework 4

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234