CVE-2010-1459

Mono < 2.6.4 - Cross-Site Scripting via __VIEWSTATE Parameter

Title source: llm
STIX 2.1

Description

The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.

Scores

EPSS 0.0041
EPSS Percentile 61.4%

Details

CWE
CWE-79
Status published
Products (50)
mono/mono 1.0
mono/mono 1.0.1
mono/mono 1.0.2
mono/mono 1.0.4
mono/mono 1.0.5
mono/mono 1.0.6
mono/mono 1.1.1
mono/mono 1.1.2
mono/mono 1.1.3
mono/mono 1.1.4
... and 40 more
Published May 27, 2010
Tracked Since Feb 18, 2026