7.5
CVSSv2

CVE-2017-0249

Published: 12/05/2017 Updated: 30/06/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft microsoft.aspnetcore.mvc.abstractions 1.1.0

microsoft microsoft.aspnetcore.mvc.abstractions 1.1.1

microsoft microsoft.aspnetcore.mvc.abstractions 1.1.2

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.0.0

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.0.1

microsoft microsoft.aspnetcore.mvc.cors 1.0.0

microsoft microsoft.aspnetcore.mvc.cors 1.0.1

microsoft microsoft.aspnetcore.mvc.cors 1.0.2

microsoft microsoft.aspnetcore.mvc.cors 1.0.3

microsoft microsoft.aspnetcore.mvc.formatters.json 1.0.3

microsoft microsoft.aspnetcore.mvc.formatters.json 1.1.0

microsoft microsoft.aspnetcore.mvc.formatters.json 1.1.1

microsoft microsoft.aspnetcore.mvc.formatters.json 1.1.2

microsoft microsoft.aspnetcore.mvc.localization 1.1.2

microsoft microsoft.aspnetcore.mvc.razor 1.0.0

microsoft microsoft.aspnetcore.mvc.razor 1.0.1

microsoft microsoft.aspnetcore.mvc.razor 1.0.2

microsoft microsoft.aspnetcore.mvc.taghelpers 1.0.1

microsoft microsoft.aspnetcore.mvc.taghelpers 1.0.2

microsoft microsoft.aspnetcore.mvc.taghelpers 1.0.3

microsoft microsoft.aspnetcore.mvc.taghelpers 1.1.0

microsoft microsoft.aspnetcore.mvc.taghelpers 1.1.1

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.1.0

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.1.1

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.1.2

microsoft system.net.http 4.1.1

microsoft asp.net model view controller 1.0.1

microsoft microsoft.aspnetcore.mvc.abstractions 1.0.1

microsoft microsoft.aspnetcore.mvc.abstractions 1.0.3

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.0.3

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.1.1

microsoft asp.net model view controller 1.0.3

microsoft asp.net model view controller 1.1.1

microsoft microsoft.aspnetcore.mvc.cors 1.1.1

microsoft microsoft.aspnetcore.mvc.dataannotations 1.0.0

microsoft microsoft.aspnetcore.mvc.formatters.json 1.0.0

microsoft microsoft.aspnetcore.mvc.formatters.json 1.0.2

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.0.0

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.0.2

microsoft microsoft.aspnetcore.mvc.localization 1.0.2

microsoft microsoft.aspnetcore.mvc.localization 1.1.0

microsoft microsoft.aspnetcore.mvc.razor 1.1.0

microsoft microsoft.aspnetcore.mvc.razor 1.1.2

microsoft microsoft.aspnetcore.mvc.razor.host 1.1.0

microsoft microsoft.aspnetcore.mvc.razor.host 1.1.2

microsoft microsoft.aspnetcore.mvc.taghelpers 1.1.2

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.0.1

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.0.1

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.0.3

microsoft system.net.http 4.3.1

microsoft system.net.http.winhttphandler 4.3.0

microsoft asp.net model view controller 1.1.0

microsoft asp.net model view controller 1.1.2

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.1.2

microsoft asp.net model view controller 1.0.0

microsoft asp.net model view controller 1.0.2

microsoft microsoft.aspnetcore.mvc.dataannotations 1.0.2

microsoft microsoft.aspnetcore.mvc.dataannotations 1.0.3

microsoft microsoft.aspnetcore.mvc.dataannotations 1.1.0

microsoft microsoft.aspnetcore.mvc.dataannotations 1.1.1

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.1.0

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.1.1

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.1.2

microsoft microsoft.aspnetcore.mvc.localization 1.0.0

microsoft microsoft.aspnetcore.mvc.razor.host 1.0.0

microsoft microsoft.aspnetcore.mvc.razor.host 1.0.1

microsoft microsoft.aspnetcore.mvc.razor.host 1.0.2

microsoft microsoft.aspnetcore.mvc.razor.host 1.0.3

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.0.3

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.1.0

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.1.1

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.1.2

microsoft system.net.security 4.3.0

microsoft system.net.websockets.client 4.0.0

microsoft system.net.websockets.client 4.3.0

microsoft system.text.encodings.web 4.0.0

microsoft system.text.encodings.web 4.3.0

microsoft microsoft.aspnetcore.mvc.abstractions 1.0.0

microsoft microsoft.aspnetcore.mvc.abstractions 1.0.2

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.0.2

microsoft microsoft.aspnetcore.mvc.apiexplorer 1.1.0

microsoft microsoft.aspnetcore.mvc.cors 1.1.0

microsoft microsoft.aspnetcore.mvc.cors 1.1.2

microsoft microsoft.aspnetcore.mvc.dataannotations 1.0.1

microsoft microsoft.aspnetcore.mvc.dataannotations 1.1.2

microsoft microsoft.aspnetcore.mvc.formatters.json 1.0.1

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.0.1

microsoft microsoft.aspnetcore.mvc.formatters.xml 1.0.3

microsoft microsoft.aspnetcore.mvc.localization 1.0.1

microsoft microsoft.aspnetcore.mvc.localization 1.0.3

microsoft microsoft.aspnetcore.mvc.localization 1.1.1

microsoft microsoft.aspnetcore.mvc.razor 1.0.3

microsoft microsoft.aspnetcore.mvc.razor 1.1.1

microsoft microsoft.aspnetcore.mvc.razor.host 1.1.1

microsoft microsoft.aspnetcore.mvc.taghelpers 1.0.0

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.0.0

microsoft microsoft.aspnetcore.mvc.viewfeatures 1.0.2

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.0.0

microsoft microsoft.aspnetcore.mvc.webapicompatshim 1.0.2

microsoft system.net.http.winhttphandler 4.0.1

microsoft system.net.security 4.0.0

Github Repositories

DotNetTest A minimal C# application that deliberately references NuGet packages with known vulnerabilities While the following components are included as references in the project file DotNetTestcsproj, the only file containing code, Programcs, does not reference any of these vulnerable components Components referenced Component ID Version Highest CVSS Score CVE ID(s)

A .net client for OSSIndex (https://ossindex.sonatype.org/)

OssIndexClient A net client for OSSIndex (ossindexsonatypeorg/) See Milestones for release notes NuGet package nugetorg/packages/OssIndexClient/ Usage Getting a report using var ossIndexClient = new OssIndex(); var report = await ossIndexClientGetReport( new( ecoSystem: EcoSystemnuget, name: "SystemNetHttp", ve