MS11-066: Vulnerability in Microsoft Chart Control Could Allow Information Disclosure (2567943)

This script is Copyright (C) 2011-2015 Tenable Network Security, Inc.

Synopsis :

The remote Windows host has an ASP.NET control that could allow
information disclosure.

Description :

An information disclosure vulnerability exists in the version of
Microsoft Chart Control installed on the remote Windows host due to
improper handling of special characters in the URI included in an HTTP
GET request.

If a web application hosted on the affected system uses Microsoft
Chart Control, an unauthenticated, remote attacker could leverage this
vulnerability to read the contents of files located in or under the
web site directory. This may result in the disclosure of sensitive
information that could be used in secondary attacks, especially in the
case of the application's web.config.

See also :

Solution :

Microsoft has released a set of patches for .NET Framework 4.0 and
Chart Control for Microsoft .NET Framework 3.5 Service Pack 1.

Risk factor :

Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.6
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 55796 ()

Bugtraq ID: 48985

CVE ID: CVE-2011-1977