4.3
CVSSv2

CVE-2012-0007

Published: 10/01/2012 Updated: 12/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote malicious users to conduct cross-site scripting (XSS) attacks via HTML input, aka "AntiXSS Library Bypass Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft anti-cross site scripting library 3.1

microsoft anti-cross site scripting library 4.0

Exploits

source: wwwsecurityfocuscom/bid/51291/info Microsoft Anti-Cross Site Scripting (AntiXSS) Library is prone to a security-bypass vulnerability that affects the sanitization module An attacker can exploit this vulnerability to bypass the filter and conduct cross-site scripting attacks Successful exploits may allow attackers to execute arb ...