Microsoft ASP.NET Unicode字符转换多个跨站脚本攻击漏洞

Microsoft ASP.NET Unicode字符转换多个跨站脚本攻击漏洞

漏洞ID 1108462 漏洞类型 跨站脚本
发布时间 2005-02-16 更新时间 2005-02-16
图片[1]-Microsoft ASP.NET Unicode字符转换多个跨站脚本攻击漏洞-安全小百科CVE编号 CVE-2005-0452
图片[2]-Microsoft ASP.NET Unicode字符转换多个跨站脚本攻击漏洞-安全小百科CNNVD-ID CNNVD-200502-063
漏洞平台 ASP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/25110
https://www.securityfocus.com/bid/12574
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200502-063
|漏洞详情
ASP.NET是由微软在.NETFramework中所提供的,开发Web应用程序的类库。MicrosoftASP.NET(.Net)1.0和1.1至SP1中的多个跨站脚本攻击(XSS)漏洞,可让远程攻击者通过Unicode表示法将ASCII全角字符转换为一般ASCII字符(包括”>”和”<“)来注入任意HTML或Web脚本。
|漏洞EXP
source: http://www.securityfocus.com/bid/12574/info

It is reported that ASP.NET is prone to various cross-site scripting attacks. These issues when ASP.NET converts Unicode characters ranging from U+ff00-U+ff60 to ASCII.

Apparently, the application fails to properly validate Unicode characters allowing an attacker to craft a malicious link containing arbitrary HTML or script code to be executed in a user's browser.

This can facilitate theft of cookie-based credentials and other attacks.

http://www.example.com/attack1.aspx?test=%uff1cscript%uff1ealert('vulnerability')%uff1c/script%uff1e
|受影响的产品
Microsoft ASP.NET 1.1 SP1

Microsoft ASP.NET 1.1

Microsoft ASP.NET 1.0 SP2

Microsoft ASP.NET 1.0 SP1

Microsoft ASP.NET 1.0

|参考资料

来源:BID
名称:12574
链接:http://www.securityfocus.com/bid/12574
来源:SECUNIA
名称:14214
链接:http://secunia.com/advisories/14214
来源:BUGTRAQ
名称:20050217XSSvulnerabiltyinASP.Net[withdetails]
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=110867912714913&w;=2
来源:MISC
链接:http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml

相关推荐: phpAnyVote Cookie Security Bypass Vulnerability

phpAnyVote Cookie Security Bypass Vulnerability 漏洞ID 1102182 漏洞类型 Design Error 发布时间 2002-04-17 更新时间 2002-04-17 CVE编号 N/A CNNVD-ID …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享