6.4

CVE-2010-3332

Exploit

Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
Microsoft.Net Framework Version1.1 Updatesp1
Microsoft.Net Framework Version2.0 Updatesp1
Microsoft.Net Framework Version2.0 Updatesp2
Microsoft.Net Framework Version3.5 Update-
Microsoft.Net Framework Version3.5 Updatesp1
Microsoft.Net Framework Version3.5.1
Microsoft.Net Framework Version4.0 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 87.27% 0.994
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-209 Generation of Error Message Containing Sensitive Information

The product generates an error message that includes sensitive information about its environment, users, or associated data.

http://securitytracker.com/id?1024459
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/43316
Third Party Advisory
VDB Entry