.NET Framework contains a flaw that allows a remote attacker to access files outside of the web path. The issue is due to ASP.NET not properly sanitizing URLs, which may allow an attacker to gain unauthorized access to files.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
OSVDB:
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.