CVE-2010-1459
ASP.NET Mono <2.6.4 - XSS
Title source: llmDescription
The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.
References (6)
Scores
EPSS
0.0041
EPSS Percentile
61.0%
Classification
CWE
CWE-79
Status
published
Affected Products (50)
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
mono/mono
... and 35 more
Timeline
Published
May 27, 2010
Tracked Since
Feb 18, 2026