The default configuration of ASP.NET in Mono before 2.6.4 has...
Vulnerability Description
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-1459
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.mono-project.com/Vulnerabilities#ASP.NET_View_State_Cross-Site_Scripting
- http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/04/29/asp-net-cross-site-scripting-followup-mono.aspx
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
- http://www.securityfocus.com/bid/40351
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
More from mono
View All →Affected Vendor
mono
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.