CVE Vulnerabilities

CVE-2015-1648

Published: Apr 14, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sensitive configuration-file information via a crafted request, aka ASP.NET Information Disclosure Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
.net_frameworkMicrosoft1.1-sp1 (including)1.1-sp1 (including)
.net_frameworkMicrosoft2.0-sp2 (including)2.0-sp2 (including)
.net_frameworkMicrosoft3.5 (including)3.5 (including)
.net_frameworkMicrosoft3.5.1 (including)3.5.1 (including)
.net_frameworkMicrosoft4.0 (including)4.0 (including)
.net_frameworkMicrosoft4.5 (including)4.5 (including)
.net_frameworkMicrosoft4.5.1 (including)4.5.1 (including)
.net_frameworkMicrosoft4.5.2 (including)4.5.2 (including)

References