CVE-2010-1459

Description

The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.41

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2010-1459 are fixed in Nuget - mono 2.6.4Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.0.5Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.0Windows
Vulnerabilities CVE-2006-5072,CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 2.0Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.13Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.13.4Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.13.6Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.13.7Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.17Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.17.1Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.18Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.4Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.1.8.3Windows
Multiple Vulnerabilities are affected in Mono for Windows 1.2.5.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.0.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.0.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.0.4Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.0.6Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.10Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.10.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.11Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.12Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.12.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.13.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.13.5Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.13.8Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.13.8.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.14Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.15Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.16Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.16.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.17.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.3Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.5Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.6Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.7Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.8Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.8.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.9Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.9.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.1.9.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.2.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.2.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.2.2.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.2.3Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.2.3.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.2.4Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.2.5Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.2.5.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.2.6Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.9Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 1.9.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 2.0.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 2.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 2.4Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 2.4.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 2.4.2.1Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 2.4.2.2Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 2.4.2.3Windows
Vulnerabilities CVE-2010-1459,CVE-2010-4159 are affected in Mono for Windows 2.4.3Windows
Mono is a platform for running and developing applications (USN-1517-1) libmono-system-web2.0-cil_2.10.8.1-1ubuntu2.3_all.debLinux
Mono is a platform for running and developing applications (USN-1517-1) libmono-system-web4.0-cil_2.10.8.1-1ubuntu2.3_all.debLinux
Vulnerabilities CVE-2010-1459 are fixed in Nuget - mono for Linux 2.6.4Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234