Security Advisory

CVE-2010-2088

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-05-27 18:32:00
Last updated 2024-09-16 22:21:05
Assigner mitre
State PUBLISHED

Description

ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks against the form control via the __VIEWSTATE parameter.