4.3
CVSSv2

CVE-2010-1459

Published: 27/05/2010 Updated: 09/09/2010
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The default configuration of ASP.NET in Mono prior to 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote malicious users to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.

Vulnerable Product Search on Vulmon Subscribe to Product

mono mono 1.1.17

mono mono 1.1.13.7

mono mono 2.4.2.2

mono mono 2.4.2.1

mono mono 1.2.6

mono mono 1.2.5.2

mono mono 1.2.1

mono mono 1.2

mono mono 1.1.13.2

mono mono 1.1.12.1

mono mono 1.1.9

mono mono 1.1.8.1

mono mono 1.1.1

mono mono 1.0.6

mono mono 1.2.5.1

mono mono 1.1.8.3

mono mono 1.1.13.6

mono mono 1.1.13.4

mono mono 2.4.2

mono mono 2.4

mono mono 1.2.5

mono mono 1.2.4

mono mono 1.1.16.1

mono mono 1.1.16

mono mono 1.1.12

mono mono 1.1.11

mono mono 1.1.8

mono mono 1.1.7

mono mono 1.0.4

mono mono 1.0.2

mono mono 1.1.17.1

mono mono 1.1.17.2

mono mono 1.0

mono mono 2.4.3

mono mono 2.4.2.3

mono mono 1.9.1

mono mono 1.9

mono mono 1.2.2.1

mono mono 1.2.2

mono mono 1.1.13.8.1

mono mono 1.1.13.8

mono mono 1.1.13.5

mono mono 1.1.9.2

mono mono 1.1.9.1

mono mono 1.1.3

mono mono 1.1.2

mono mono 1.1.4

mono mono 1.1.18

mono mono 1.1.13

mono mono 1.0.5

mono mono 2.2

mono mono 2.0.1

mono mono 1.2.3.1

mono mono 1.2.3

mono mono 1.1.15

mono mono 1.1.14

mono mono 1.1.10.1

mono mono 1.1.10

mono mono 1.1.6

mono mono 1.1.5

mono mono 1.0.1

mono mono 2.0

Vendor Advisories

Debian Bug report logs - #585440 mono: CVE-2010-1459 insecure default configuration of EnableViewStateMac property might lead to XSS Package: mono; Maintainer for mono is Debian Mono Group <pkg-mono-group@listsaliothdebianorg>; Reported by: Nico Golde <nion@debianorg> Date: Thu, 10 Jun 2010 14:48:02 UTC Severity: ...