CVE-2012-3382
published 2012-07-12CVE-2012-3382: Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.91%
77.7th percentile
Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mono | < mono 2.10.8.1-5 (bookworm) | mono 2.10.8.1-5 (bookworm) |
| mono | mono | <= 2.10.8 | — |
| mono | mono | >= 0 < 2.10.8.1-5 | 2.10.8.1-5 |
| mono | mono | >= 0 < 2.10.8.1-5 | 2.10.8.1-5 |
| mono | mono | >= 0 < 2.10.8.1-5 | 2.10.8.1-5 |
| mono | mono | >= 0 < 2.10.8.1-5 | 2.10.8.1-5 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mono vulnerabilities
vendor_ubuntu·2012-07-25·CVSS 6.9
CVE-2010-4159 [MEDIUM] Mono vulnerabilities
Title: Mono vulnerabilities
Summary: Mono could be made to expose sensitive information over the network.
It was discovered that the Mono System.Web library incorrectly filtered
certain error messages related to forbidden files. If a user were tricked
into opening a specially crafted URL, an attacker could possibly exploit
this to conduct cross-site scripting (XSS) attacks. (CVE-2012-3382)
It was discovered that the Mono System.Web library incorrectly handled the
EnableViewStateMac property. If a user were tricked into opening a
specially crafted URL, an attacker could possibly exploit this to conduct
cross-site scripting (XSS) attacks. This issue only affected Ubuntu
10.04 LTS. (CVE-2010-4159)
Instructions: After a standard system update you need to restart Mono applications to
make a
Debian
CVE-2012-3382: mono - Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/c...
vendor_debian·2012·CVSS 4.3
CVE-2012-3382 [MEDIUM] CVE-2012-3382: mono - Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/c...
Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message.
Scope: local
bookworm: resolved (fixed in 2.10.8.1-5)
bullseye: resolved (fixed in 2.10.8.1-5)
forky: resolved (fixed in 2.10.8.1-5)
sid: resolved (fixed in 2.10.8.1-5)
trixie: resolved (fixed in 2.10.8.1-5)
GHSA
GHSA-hfwc-qwvw-crw5: Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System
ghsa_unreviewed·2022-05-17
CVE-2012-3382 [MEDIUM] CWE-79 GHSA-hfwc-qwvw-crw5: Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System
Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message.
OSV
CVE-2012-3382: Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System
osv·2012-07-12·CVSS 4.3
CVE-2012-3382 [MEDIUM] CVE-2012-3382: Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System
Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3382 mono: XSS in ProcessRequest function [epel-6]
bugzilla·2012-07-13·CVSS 4.3
CVE-2012-3382 [MEDIUM] CVE-2012-3382 mono: XSS in ProcessRequest function [epel-6]
CVE-2012-3382 mono: XSS in ProcessRequest function [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=839976
ep
Bugzilla
CVE-2012-3382 mono: XSS in ProcessRequest function
bugzilla·2012-07-13·CVSS 4.3
CVE-2012-3382 [MEDIUM] CVE-2012-3382 mono: XSS in ProcessRequest function
CVE-2012-3382 mono: XSS in ProcessRequest function
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-3382 to the following vulnerability:
Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message.
References:
[1] http://www.openwall.com/lists/oss-security/2012/07/06/11
[2] https://bugzilla.novell.com/show_bug.cgi?id=769799
Upstream patch:
[3] https://github.com/mono/mono/commit/d16d4623edb210635bec3ca3786481b82cde25a2
Discussion:
This issue affects the (current) versions of the mono package, as ship
Bugzilla
CVE-2012-3382 mono: XSS in ProcessRequest function [fedora-all]
bugzilla·2012-07-13·CVSS 4.3
CVE-2012-3382 [MEDIUM] CVE-2012-3382 mono: XSS in ProcessRequest function [fedora-all]
CVE-2012-3382 mono: XSS in ProcessRequest function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=839976
http://www.mandriva.com/security/advisories?name=MDVSA-2012:140http://www.openwall.com/lists/oss-security/2012/07/06/11https://bugzilla.novell.com/show_bug.cgi?id=769799https://github.com/mono/mono/commit/d16d4623edb210635bec3ca3786481b82cde25a2https://hermes.opensuse.org/messages/15374367http://www.mandriva.com/security/advisories?name=MDVSA-2012:140http://www.openwall.com/lists/oss-security/2012/07/06/11https://bugzilla.novell.com/show_bug.cgi?id=769799https://github.com/mono/mono/commit/d16d4623edb210635bec3ca3786481b82cde25a2https://hermes.opensuse.org/messages/15374367
2012-07-12
Published