VulnerabilityModified
CVE-2010-2085
The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.
MEDIUM 4.3EPSS 9.00%
Does this matter?
Lower severity and a low EPSS score (9.00%). Track it; it rarely justifies an emergency change on its own.
Description
The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 9.00% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/.net framework
- Source
- cve@mitre.org
References
- http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdfExploit
- https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txtExploit
- http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdfExploit
- https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txtExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.