← Vulnerability feed

Vulnerability record · CVE-2006-6104 · published 21 December 2006

CVE-2006-6104: Mono xsp vulnerability

Mono · Xsp

The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.

5.0 CVSS 2.0 Medium EPSS 5.2% · top 7.8%
5.0CVSS 2.0 base score
5.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
40References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appending a space (%20) to a URI, and (2) read credentials via a request for Web.Config%20.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://fedoranews.org/cms/node/2400
http://fedoranews.org/cms/node/2401
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0002.html
http://secunia.com/advisories/23432 ExploitPatchVendor Advisory
http://secunia.com/advisories/23435 PatchVendor Advisory
http://secunia.com/advisories/23462 PatchVendor Advisory
http://secunia.com/advisories/23597
http://secunia.com/advisories/23727
http://secunia.com/advisories/23776
http://secunia.com/advisories/23779
http://security.gentoo.org/glsa/glsa-200701-12.xml
http://securityreason.com/securityalert/2082
http://securitytracker.com/id?1017430
http://www.eazel.es/advisory007-mono-xsp-source-disclosure-vulnerability.html Exploit
http://www.mandriva.com/security/advisories?name=MDKSA-2006:234 PatchVendor Advisory
http://www.securityfocus.com/archive/1/454962/100/0/threaded
http://www.securityfocus.com/bid/21687 ExploitPatch
http://www.ubuntu.com/usn/usn-397-1 Patch
http://www.vupen.com/english/advisories/2006/5099
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2092
http://fedoranews.org/cms/node/2400
http://fedoranews.org/cms/node/2401
http://lists.suse.com/archive/suse-security-announce/2007-Jan/0002.html
http://secunia.com/advisories/23432 ExploitPatchVendor Advisory
http://secunia.com/advisories/23435 PatchVendor Advisory
http://secunia.com/advisories/23462 PatchVendor Advisory
http://secunia.com/advisories/23597
http://secunia.com/advisories/23727
http://secunia.com/advisories/23776
http://secunia.com/advisories/23779
http://security.gentoo.org/glsa/glsa-200701-12.xml
http://securityreason.com/securityalert/2082
http://securitytracker.com/id?1017430
http://www.eazel.es/advisory007-mono-xsp-source-disclosure-vulnerability.html Exploit
http://www.mandriva.com/security/advisories?name=MDKSA-2006:234 PatchVendor Advisory
http://www.securityfocus.com/archive/1/454962/100/0/threaded
http://www.securityfocus.com/bid/21687 ExploitPatch
http://www.ubuntu.com/usn/usn-397-1 Patch
http://www.vupen.com/english/advisories/2006/5099
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2092

Track CVE-2006-6104 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-6104), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.