4.3

CVE-2005-0452

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".

Data is provided by the National Vulnerability Database (NVD)
MicrosoftAsp.Net Version1.0
MicrosoftAsp.Net Version1.0 Updatesp1
MicrosoftAsp.Net Version1.0 Updatesp2
MicrosoftAsp.Net Version1.1
MicrosoftAsp.Net Version1.1 Updatesp1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 26.61% 0.962
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N