Mono 'EnableViewStateMac' Cross-Site Scripting Weakness
BID:40351
Info
Mono 'EnableViewStateMac' Cross-Site Scripting Weakness
| Bugtraq ID: | 40351 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1459 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2010 12:00AM |
| Updated: | May 07 2015 05:07PM |
| Credit: | Web Security Research Group (WSRG) of Hewlett Packard (HP) |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise 11 SuSE SUSE Linux Enterprise 10 SP2 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Pardus Linux 2009 0 Mono Mono 2.4.2 .1 Mono Mono 2.4.2 Mono Mono 2.0 Mono Mono 1.2.5 2 Mono Mono 1.2.5 1 Mono Mono 1.1.18 Mono Mono 1.1.17 Mono Mono 1.1.13 Mono Mono 1.1.4 Mono Mono 1.0.5 Mono Mono 1.0 Mono Mono 1.1.8.3 Mono Mono 1.1.17.1 Mono Mono 1.1.13.7 Mono Mono 1.1.13.6 Mono Mono 1.1.13.4 |
| Not Vulnerable: |
Mono Mono 2.6.4 |
Discussion
Mono 'EnableViewStateMac' Cross-Site Scripting Weakness
Mono is prone a cross-site scripting weakness.
The issue may allow attackers to perform cross-site scripting attacks. The attacker may carry out cross-site scripting attacks to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The issue affects versions prior to Mono 2.6.4.
Mono is prone a cross-site scripting weakness.
The issue may allow attackers to perform cross-site scripting attacks. The attacker may carry out cross-site scripting attacks to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
The issue affects versions prior to Mono 2.6.4.
Exploit / POC
Mono 'EnableViewStateMac' Cross-Site Scripting Weakness
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI or visit a malicious website.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI or visit a malicious website.
Solution / Fix
Mono 'EnableViewStateMac' Cross-Site Scripting Weakness
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Mono 'EnableViewStateMac' Cross-Site Scripting Weakness
References:
References:
- ASP.NET Cross-Site Scripting Followup: Mono (bob.thomas)
- Configuration is Half the Battle: ASP.NET and Cross-Site Scripting (bob.thomas)
- Mono Homepage (Mono)
- ASP.NET View State Cross-Site Scripting (Mono)