CVE-2010-2085
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
27/05/2010
Last modified:
11/04/2025
Description
The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:microsoft:.net_framework:*:sp3:*:*:*:*:*:* | 1.0 (including) | |
| cpe:2.3:a:microsoft:.net_framework:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:.net_framework:1.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:.net_framework:1.0:gold:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:.net_framework:1.0:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:.net_framework:1.0:sp2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf
- https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt
- http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf
- https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt



