CVE-2010-1459
published 2010-05-27CVE-2010-1459: The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.93%
77.8th percentile
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mono | < mono 2.4.4~svn151842-3 (bookworm) | mono 2.4.4~svn151842-3 (bookworm) |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
| mono | mono | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mono ASP.NET View State Cross-Site Scripting (XSS) vulnerability
osv·2022-05-02
CVE-2010-1459 [MEDIUM] Mono ASP.NET View State Cross-Site Scripting (XSS) vulnerability
Mono ASP.NET View State Cross-Site Scripting (XSS) vulnerability
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
GHSA
Mono ASP.NET View State Cross-Site Scripting (XSS) vulnerability
ghsa·2022-05-02
CVE-2010-1459 [MEDIUM] CWE-79 Mono ASP.NET View State Cross-Site Scripting (XSS) vulnerability
Mono ASP.NET View State Cross-Site Scripting (XSS) vulnerability
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
OSV
CVE-2010-1459: The default configuration of ASP
osv·2010-05-27·CVSS 4.3
CVE-2010-1459 [MEDIUM] CVE-2010-1459: The default configuration of ASP
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
Red Hat
Mono: View State Cross-Site Scripting
vendor_redhat·2010-04-28·CVSS 4.3
CVE-2010-1459 [MEDIUM] CWE-79 Mono: View State Cross-Site Scripting
Mono: View State Cross-Site Scripting
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
Debian
CVE-2010-1459: mono - The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE f...
vendor_debian·2010·CVSS 4.3
CVE-2010-1459 [MEDIUM] CVE-2010-1459: mono - The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE f...
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
Scope: local
bookworm: resolved (fixed in 2.4.4~svn151842-3)
bullseye: resolved (fixed in 2.4.4~svn151842-3)
forky: resolved (fixed in 2.4.4~svn151842-3)
sid: resolved (fixed in 2.4.4~svn151842-3)
trixie: resolved (fixed in 2.4.4~svn151842-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1459 Mono: View State Cross-Site Scripting [Fedora all]
bugzilla·2010-05-31·CVSS 4.3
CVE-2010-1459 [MEDIUM] CVE-2010-1459 Mono: View State Cross-Site Scripting [Fedora all]
CVE-2010-1459 Mono: View State Cross-Site Scripting [Fedora all]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in affected Fedora versions.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #598155:
CVE-2010-1459 Mono: View State Cross-Site Scripting
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product. Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=598155
Please note: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2010-1459 Mono: View State Cross-Site Scripting
bugzilla·2010-05-31·CVSS 4.3
CVE-2010-1459 [MEDIUM] CVE-2010-1459 Mono: View State Cross-Site Scripting
CVE-2010-1459 Mono: View State Cross-Site Scripting
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1459 to
the following vulnerability:
The default configuration of ASP.NET in Mono before 2.6.4 has a value
of FALSE for the EnableViewStateMac property, which allows remote
attackers to conduct cross-site scripting (XSS) attacks, as
demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in
the XSP sample project.
Upstream patch:
[1] http://anonsvn.mono-project.com/viewvc?view=revision&revision=154493
References:
[2] http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/04/29/asp-net-cross-site-scripting-followup-mono.aspx
[3] http://www.mono-project.com/Vulnerabilities#ASP.NET_View_State_Cross-Site_Scripting
[4] http://lists.opensuse.org
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/04/29/asp-net-cross-site-scripting-followup-mono.aspxhttp://www.mono-project.com/Vulnerabilities#ASP.NET_View_State_Cross-Site_Scriptinghttp://www.securityfocus.com/bid/40351http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/04/29/asp-net-cross-site-scripting-followup-mono.aspxhttp://www.mono-project.com/Vulnerabilities#ASP.NET_View_State_Cross-Site_Scriptinghttp://www.securityfocus.com/bid/40351
2010-05-27
Published