|
|
| |
|
| |
mono: cross-site scripting
| Package(s): | mono |
CVE #(s): | CVE-2010-1459
|
| Created: | June 15, 2010 |
Updated: | July 26, 2012 |
| Description: |
From the Pardus advisory:
The default configuration of ASP.NET in Mono before 2.6.4 has a value of
FALSE for the EnableViewStateMac property, which allows remote attackers
to conduct cross-site scripting (XSS) attacks, as demonstrated by the
__VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project. |
| Alerts: |
|
( Log in to post comments)
|
|
|