4.3

CVE-2008-3843

Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "<~/" (less-than tilde slash) sequence followed by a crafted STYLE element.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft.Net Framework Version1.0 Updatesp3
   MicrosoftWindows-nt Version2003 Updategold Editionserver_x64
   MicrosoftWindows-nt Version2003 Updatesp1 Editionserver
   MicrosoftWindows-nt Version2003 Updatesp1 Editionserver_itanium
   MicrosoftWindows-nt Version2003 Updatesp2 Editionserver
   MicrosoftWindows-nt Version2003 Updatesp2 Editionserver_itanium
   MicrosoftWindows-nt Version2003 Updatesp2 Editionserver_x64
   MicrosoftWindows-nt Version2008
   MicrosoftWindows-nt Versionxp Updategold Editionmedia_center_2005
   MicrosoftWindows-nt Versionxp Updategold Editiontablet_pc_2005
   MicrosoftWindows-nt Versionxp Updategold Editionx64
   MicrosoftWindows-nt Versionxp Updatesp3
   MicrosoftWindows 2000 Updatesp4
   MicrosoftWindows Vista
   MicrosoftWindows Vista Version- Updatesp1
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionx64
Microsoft.Net Framework Version1.1 Updatesp1
   MicrosoftWindows-nt Version2003 Updategold Editionserver_x64
   MicrosoftWindows-nt Version2003 Updatesp1 Editionserver
   MicrosoftWindows-nt Version2003 Updatesp1 Editionserver_itanium
   MicrosoftWindows-nt Version2003 Updatesp2 Editionserver
   MicrosoftWindows-nt Version2003 Updatesp2 Editionserver_itanium
   MicrosoftWindows-nt Version2003 Updatesp2 Editionserver_x64
   MicrosoftWindows-nt Version2008
   MicrosoftWindows-nt Version2008 Editionitanium
   MicrosoftWindows-nt Version2008 Editionx64
   MicrosoftWindows-nt Versionvista Updatesp1 Editionx64
   MicrosoftWindows-nt Versionxp Updategold Editionx64
   MicrosoftWindows-nt Versionxp Updatesp3
   MicrosoftWindows 2000 Updatesp4
   MicrosoftWindows Vista
   MicrosoftWindows Vista Updategold Editionx64
   MicrosoftWindows Vista Version- Updatesp1
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionx64
Microsoft.Net Framework Version2.0
   MicrosoftWindows-nt Version2003 Updategold Editionserver_x64
   MicrosoftWindows-nt Version2003 Updatesp1 Editionserver
   MicrosoftWindows-nt Version2003 Updatesp1 Editionserver_itanium
   MicrosoftWindows-nt Version2003 Updatesp2 Editionserver
   MicrosoftWindows-nt Version2003 Updatesp2 Editionserver_itanium
   MicrosoftWindows-nt Version2003 Updatesp2 Editionserver_x64
   MicrosoftWindows-nt Versionxp Updategold Editionx64
   MicrosoftWindows-nt Versionxp Updatesp3
   MicrosoftWindows 2000 Updatesp4
   MicrosoftWindows Vista
   MicrosoftWindows Vista Updategold Editionx64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionx64
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.67% 0.934
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.