Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5c6-w479-93xm

Опубликовано: 02 мая 2022
Источник: github
Github: Прошло ревью

Описание

Mono ASP.NET View State Cross-Site Scripting (XSS) vulnerability

The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.

Пакеты

Наименование

mono

nuget
Затронутые версииВерсия исправления

< 2.6.4

2.6.4

EPSS

Процентиль: 61%
0.0041
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 15 лет назад

The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.

redhat
больше 15 лет назад

The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.

nvd
больше 15 лет назад

The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.

debian
больше 15 лет назад

The default configuration of ASP.NET in Mono before 2.6.4 has a value ...

EPSS

Процентиль: 61%
0.0041
Низкий

Дефекты

CWE-79