CVE-2010-1459
Mono < 2.6.4 - Cross-Site Scripting via __VIEWSTATE Parameter
Title source: llmDescription
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
References (6)
Core 6
Core References
Vendor Advisory x_refsource_confirm
http://www.mono-project.com/Vulnerabilities#ASP.NET_View_State_Cross-Site_Scripting
Various Sources x_refsource_misc
http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/04/29/asp-net-cross-site-scripting-followup-mono.aspx
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/40351
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
Scores
EPSS
0.0041
EPSS Percentile
61.4%
Details
CWE
CWE-79
Status
published
Products (50)
mono/mono
1.0
mono/mono
1.0.1
mono/mono
1.0.2
mono/mono
1.0.4
mono/mono
1.0.5
mono/mono
1.0.6
mono/mono
1.1.1
mono/mono
1.1.2
mono/mono
1.1.3
mono/mono
1.1.4
... and 40 more
Published
May 27, 2010
Tracked Since
Feb 18, 2026