CVE-2011-1977: Infoleak
The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP request, aka "Chart Control Information Disclosure Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1977?
CVE-2011-1977 has a severity rating that indicates a risk of information disclosure due to improper URI function verification in ASP.NET Chart controls.
How do I fix CVE-2011-1977?
To fix CVE-2011-1977, apply the latest security update for Microsoft .NET Framework that addresses the vulnerability.
What versions of Microsoft products are affected by CVE-2011-1977?
CVE-2011-1977 affects Microsoft .NET Framework 3.5 SP1 and 4.0 running on specific Windows operating systems.
What types of attacks are possible with CVE-2011-1977?
CVE-2011-1977 allows remote attackers to read arbitrary files on the server through specially crafted URIs.
Is my application using ASP.NET Chart controls vulnerable to CVE-2011-1977?
If your application uses ASP.NET Chart controls in Microsoft .NET Framework 3.5 SP1 or 4.0, it may be vulnerable to CVE-2011-1977.