Microsoft has posted guidance that protects against a reported vulnerability in all versions of ASP.NET that could allow a Web site visitor to view secured content by using specially crafted requests to a Web server.
This vulnerability affects the majority of ASP.NET applications.
http://www.microsoft.com/security/incident/aspnet.mspx