Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-1459
Description:The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
Test IDs: 1.3.6.1.4.1.25623.1.0.862240   1.3.6.1.4.1.25623.1.0.67703   1.3.6.1.4.1.25623.1.0.862244   1.3.6.1.4.1.25623.1.0.862251   1.3.6.1.4.1.25623.1.0.862252   1.3.6.1.4.1.25623.1.0.862249   1.3.6.1.4.1.25623.1.0.862243   1.3.6.1.4.1.25623.1.0.862242   1.3.6.1.4.1.25623.1.0.862246   1.3.6.1.4.1.25623.1.0.862245   1.3.6.1.4.1.25623.1.0.67702  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-1459
BugTraq ID: 40351
http://www.securityfocus.com/bid/40351
http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/04/29/asp-net-cross-site-scripting-followup-mono.aspx
SuSE Security Announcement: SUSE-SR:2010:012 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
SuSE Security Announcement: SUSE-SR:2010:013 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
SuSE Security Announcement: SUSE-SR:2010:014 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html




© 1998-2025 E-Soft Inc. All rights reserved.