CVE-2010-2085
Microsoft .NET Framework < 1.1 - Cross-Site Scripting via __VIEWSTATE Parameter
Title source: llmDescription
The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.
References (2)
Core 2
Core References
Exploit x_refsource_misc
https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt
Exploit x_refsource_misc
http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf
Scores
EPSS
0.0900
EPSS Percentile
94.8%
Details
CWE
CWE-79
Status
published
Products (2)
microsoft/.net_framework
1.0 (5 CPE variants)
microsoft/.net_framework
< 1.0
Published
May 27, 2010
Tracked Since
Feb 18, 2026