LWN.net Logo

mono: cross-site scripting

Package(s):mono CVE #(s):CVE-2010-1459
Created:June 15, 2010 Updated:July 26, 2012
Description: From the Pardus advisory:

The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.

Alerts:
SUSE SUSE-SR:2010:014 2010-08-02
Fedora FEDORA-2010-10332 2010-06-24
Pardus 2010-79 2010-06-15
Fedora FEDORA-2010-10332 2010-06-24
Fedora FEDORA-2010-10332 2010-06-24
Fedora FEDORA-2010-10332 2010-06-24
Fedora FEDORA-2010-10332 2010-06-24
Fedora FEDORA-2010-10332 2010-06-24
Fedora FEDORA-2010-10332 2010-06-24
Fedora FEDORA-2010-10433 2010-06-28
Fedora FEDORA-2010-10332 2010-06-24
Ubuntu USN-1517-1 2012-07-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds