PT-2011-2853 · Microsoft · Iis+2

Publicado

2011-02-23

·

Atualizado

2011-04-21

·

CVE-2011-1068

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows Azure Software Development Kit (SDK) versions 1.3.x before 1.3.20121.1237
Description The issue is related to the improper support of cookies for maintaining state in ASP.NET applications when used with Full IIS and a Web Role. This allows remote attackers to obtain potentially sensitive information by reading an encrypted cookie and performing other steps.
Recommendations For Microsoft Windows Azure Software Development Kit (SDK) versions 1.3.x before 1.3.20121.1237, update to version 1.3.20121.1237 or later to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1068

Produtos afetados

Asp.Net
Iis
Windows Azure Software Development Kit