Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.804038
Category:Windows
Title:Microsoft ASP.NET Insecure Site Configuration Vulnerability (2905247)
Summary:This host is missing an important security update according to Microsoft; advisory (2905247).
Description:Summary:
This host is missing an important security update according to Microsoft
advisory (2905247).

Vulnerability Insight:
Flaw is due to the view state that exists when Machine Authentication Code
(MAC) validation is disabled through configuration settings.

Vulnerability Impact:
Successful exploitation will allow remote attackers to use specially crafted
HTTP content to inject code to be run in the context of the service account on the ASP.NET server.

Affected Software/OS:
Microsoft .NET Framework versions 1.1, 2.0, 3.5, 3.5.1, 4.0, 4.5 and 4.5.1.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

CopyrightCopyright (C) 2013 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.