CVE-2008-3422

Description

Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.65

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Mono for Windows 1.0.5Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.0Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.13Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.13.4Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.13.6Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.13.7Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.17Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.17.1Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.18Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.4Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.8.3Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.2.5.1Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234