CVE-2008-3422
published 2008-07-31CVE-2008-3422: Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.55%
72.4th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mono | < mono 1.9.1+dfsg-4 (bookworm) | mono 1.9.1+dfsg-4 (bookworm) |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | >= 0 < 1.9.1+dfsg-4 | 1.9.1+dfsg-4 |
| mono | mono | >= 0 < 1.9.1+dfsg-4 | 1.9.1+dfsg-4 |
| mono | mono | >= 0 < 1.9.1+dfsg-4 | 1.9.1+dfsg-4 |
| mono | mono | >= 0 < 1.9.1+dfsg-4 | 1.9.1+dfsg-4 |
| mono_project | mono | <= 2.0 | — |
| mono_project | mono | — | — |
| mono_project | mono | — | — |
| mono_project | mono | — | — |
| mono_project | mono | — | — |
| mono_project | mono | — | — |
| mono_project | mono | — | — |
| mono_project | mono | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mono vulnerabilities
vendor_ubuntu·2009-08-26·CVSS 4.3
CVE-2009-0217 [MEDIUM] Mono vulnerabilities
Title: Mono vulnerabilities
Summary: Mono vulnerabilities
It was discovered that the XML HMAC signature system did not correctly
check certain lengths. If an attacker sent a truncated HMAC, it could
bypass authentication, leading to potential privilege escalation.
(CVE-2009-0217)
It was discovered that Mono did not properly escape certain attributes in
the ASP.net class libraries which could result in browsers becoming
vulnerable to cross-site scripting attacks when processing the output. With
cross-site scripting vulnerabilities, if a user were tricked into viewing
server output during a crafted server request, a remote attacker could
exploit this to modify the contents, or steal confidential data (such as
passwords), within the same domain. This issue only affected Ubuntu 8.04
LTS. (C
Red Hat
mono: XSS vulnerabilities in the ASP.net class libraries
vendor_redhat·2008-07-31·CVSS 4.3
CVE-2008-3422 [MEDIUM] CWE-79 mono: XSS vulnerabilities in the ASP.net class libraries
mono: XSS vulnerabilities in the ASP.net class libraries
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).
Debian
CVE-2008-3422: mono - Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class librari...
vendor_debian·2008·CVSS 4.3
CVE-2008-3422 [MEDIUM] CVE-2008-3422: mono - Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class librari...
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).
Scope: local
bookworm: resolved (fixed in 1.9.1+dfsg-4)
bullseye: resolved (fixed in 1.9.1+dfsg-4)
forky: resolved (fixed in 1.9.1+dfsg-4)
sid: resolved (fixed in 1.9.1+dfsg-4)
trixie: resolved (fixed in 1.9.1+dfsg-4)
GHSA
GHSA-xfvr-xq7r-qx2q: Multiple cross-site scripting (XSS) vulnerabilities in the ASP
ghsa_unreviewed·2022-05-02
CVE-2008-3422 [MEDIUM] CWE-79 GHSA-xfvr-xq7r-qx2q: Multiple cross-site scripting (XSS) vulnerabilities in the ASP
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).
OSV
CVE-2008-3422: Multiple cross-site scripting (XSS) vulnerabilities in the ASP
osv·2008-07-31·CVSS 4.3
CVE-2008-3422 [MEDIUM] CVE-2008-3422: Multiple cross-site scripting (XSS) vulnerabilities in the ASP
Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlhttp://lists.ximian.com/pipermail/mono-devel-list/2008-July/028633.htmlhttp://secunia.com/advisories/31338http://secunia.com/advisories/31982http://secunia.com/advisories/36494http://www.securityfocus.com/bid/30471https://bugzilla.novell.com/show_bug.cgi?id=413534https://exchange.xforce.ibmcloud.com/vulnerabilities/44229https://usn.ubuntu.com/826-1/http://lists.opensuse.org/opensuse-security-announce/2008-09/msg00004.htmlhttp://lists.ximian.com/pipermail/mono-devel-list/2008-July/028633.htmlhttp://secunia.com/advisories/31338http://secunia.com/advisories/31982http://secunia.com/advisories/36494http://www.securityfocus.com/bid/30471https://bugzilla.novell.com/show_bug.cgi?id=413534https://exchange.xforce.ibmcloud.com/vulnerabilities/44229https://usn.ubuntu.com/826-1/
2008-07-31
Published