Microsoft ASP.NET AutoPostBack Variable Cross-Site Scripting Vulnerability
BID:20337
Info
Microsoft ASP.NET AutoPostBack Variable Cross-Site Scripting Vulnerability
| Bugtraq ID: | 20337 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3436 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2006 12:00AM |
| Updated: | Oct 13 2006 05:09PM |
| Credit: | Jaswinder Hayre discovered this vulnerability. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows 2000 Server SP4 Microsoft .NET Framework 2.0 |
| Not Vulnerable: |
Microsoft .NET Framework 1.1 SP3 Microsoft .NET Framework 1.1 SP2 Microsoft .NET Framework 1.1 SP1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.0 SP3 Microsoft .NET Framework 1.0 SP2 Microsoft .NET Framework 1.0 SP1 Microsoft .NET Framework 1.0 |
Discussion
Microsoft ASP.NET AutoPostBack Variable Cross-Site Scripting Vulnerability
Microsoft ASP.NET is prone to a cross-site scripting vulnerability because the software fails to properly sanitize user-supplied input before it is rendered in the browser of an unsuspecting user in the context of the affected site.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user, with the privileges of the victim userâ??s account. This may help the attacker steal cookie-based authentication credentials, retrieve sensitive information, and launch other attacks.
Microsoft ASP.NET is prone to a cross-site scripting vulnerability because the software fails to properly sanitize user-supplied input before it is rendered in the browser of an unsuspecting user in the context of the affected site.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user, with the privileges of the victim userâ??s account. This may help the attacker steal cookie-based authentication credentials, retrieve sensitive information, and launch other attacks.
Exploit / POC
Microsoft ASP.NET AutoPostBack Variable Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice a victim user into visiting a malicious site or following a malicious URI.
To exploit this issue, an attacker must entice a victim user into visiting a malicious site or following a malicious URI.
Solution / Fix
Microsoft ASP.NET AutoPostBack Variable Cross-Site Scripting Vulnerability
Solution:
The vendor has released fixes to address this issue; please see the reference section for details.
Microsoft .NET Framework 2.0
Solution:
The vendor has released fixes to address this issue; please see the reference section for details.
Microsoft .NET Framework 2.0
-
Microsoft .NET Framework 2.0 SYSTEM.WEB.DLL Security Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=34C375AA-2F54 -4416-B1FC-B73378492AA6
References
Microsoft ASP.NET AutoPostBack Variable Cross-Site Scripting Vulnerability
References:
References:
- Microsoft Windows Homepage (Microsoft)
- Vulnerability in ASP.NET 2.0 Could Allow Information Disclosure (922770) (Microsoft)