4.3

CVE-2005-0452

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftAsp.Net Version1.0
MicrosoftAsp.Net Version1.0 Updatesp1
MicrosoftAsp.Net Version1.0 Updatesp2
MicrosoftAsp.Net Version1.1
MicrosoftAsp.Net Version1.1 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 26.61% 0.962
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N