CVE-2008-3842
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "</" (less-than slash) sequence.
Affected (3)
Products: Microsoft: .net Framework
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1 sp1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Nt | Version 2008 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 sp3 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Nt | Version 2003 gold |
Microsoft Windows 2000 | All versions |
Microsoft Windows Vista | All versions |
Microsoft Windows Xp | All versions |
References (8)
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.