AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-6104

MEDIUM · CVSS 5 EPSS 5.12%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-12-21 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-6104
Severity
MEDIUM
CVSS
5
EPSS
5.12%

Original NVD Description

The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.