← Back

CVE-2010-1459

nvd nist
Published: May 27, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.

Affected (62)

Products: Mono: Mono
1 product
Mono
Configuration A
62 vulnerable
Vulnerable SoftwareAffected Versions
Mono
Version 1.0.1
Version 1.0.2
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0
Version 1.1.10.1
Version 1.1.10
Version 1.1.11
Version 1.1.12.1
Version 1.1.12
Version 1.1.13.2
Version 1.1.13.4
Version 1.1.13.5
Version 1.1.13.6
Version 1.1.13.7
Version 1.1.13.8.1
Version 1.1.13.8
Version 1.1.13
Version 1.1.14
Version 1.1.15
Version 1.1.16.1
Version 1.1.16
Version 1.1.17.1
Version 1.1.17.2
Version 1.1.17
Version 1.1.18
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.6
Version 1.1.7
Version 1.1.8.1
Version 1.1.8.3
Version 1.1.8
Version 1.1.9.1
Version 1.1.9.2
Version 1.1.9
Version 1.2.1
Version 1.2.2.1
Version 1.2.2
Version 1.2.3.1
Version 1.2.3
Version 1.2.4
Version 1.2.5.1
Version 1.2.5.2
Version 1.2.5
Version 1.2.6
Version 1.2
Version 1.9.1
Version 1.9
Version 2.0.1
Version 2.0
Version 2.2
Version 2.4.2.1
Version 2.4.2.2
Version 2.4.2.3
Version 2.4.2
Version 2.4.3
Version 2.4

Timeline

No history available yet.