Microsoft .NET Version Information Disclosure

info Nessus Plugin ID 24243

Synopsis

It is possible to obtain the version number of the remote installation of Microsoft .NET Framework.

Description

By requesting a non-existent .aspx file on the remote web server, it is possible to obtain the exact version number of the remote .NET framework.

Solution

Configure IIS to return custom error messages instead of the default .NET error messages by setting the option 'customErrors mode' to 'On' or 'RemoteOnly'.

Plugin Details

Severity: Info

ID: 24243

File Name: dotnet_framework_version.nasl

Version: 1.13

Type: remote

Family: Web Servers

Published: 1/26/2007

Updated: 11/14/2024

Asset Inventory: true

Supported Sensors: Nessus

Vulnerability Information

CPE: cpe:/a:microsoft:.net_framework